Vulnerabilities > Mozilla > Mozilla > 1.5.1

DATE CVE VULNERABILITY TITLE RISK
2005-03-25 CVE-2005-0585 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.
network
high complexity
mozilla
2.6
2005-03-23 CVE-2005-0143 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.
network
high complexity
mozilla
2.6
2005-03-04 CVE-2005-0593 Remote vulnerability in Mozilla Suite
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.
network
high complexity
mozilla
2.6
2005-02-08 CVE-2005-0233 The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
network
low complexity
mozilla omnigroup opera opera-software
7.5
2004-12-31 CVE-2004-1451 Remote Security vulnerability in Browser
Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrusted sites and facilitate phishing attacks.
network
high complexity
mozilla
2.6
2004-12-31 CVE-2004-1449 File-Upload vulnerability in Browser
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determine the location of files on a user's hard drive by obscuring a file upload control and tricking the user into dragging text into that control.
network
high complexity
firebirdsql mozilla
2.6
2004-12-31 CVE-2004-1156 Unspecified vulnerability in Mozilla Firefox and Mozilla
Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
network
mozilla
4.3
2004-12-31 CVE-2004-0909 Unspecified vulnerability in Mozilla and Thunderbird
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 may allow remote attackers to trick users into performing unexpected actions, including installing software, via signed scripts that request enhanced abilities using the enablePrivilege parameter, then modify the meaning of certain security-relevant dialog messages.
network
high complexity
mozilla
5.1
2004-12-31 CVE-2004-0908 Unspecified vulnerability in Mozilla and Thunderbird
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript code to read and write to the clipboard, and possibly obtain sensitive information, via script-generated events such as Ctrl-Ins.
network
high complexity
mozilla
4.0
2004-12-31 CVE-2004-0907 Unspecified vulnerability in Mozilla and Thunderbird
The Linux install .tar.gz archives for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8, create certain files with insecure permissions, which could allow local users to overwrite those files and execute arbitrary code.
local
low complexity
mozilla
4.6