Vulnerabilities > Mozilla > Mozilla > 1.7

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0147 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.
network
low complexity
mozilla
7.5
2005-05-02 CVE-2005-0146 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to obtain sensitive data from the clipboard via Javascript that generates a middle-click event on systems for which a middle-click performs a paste operation.
network
low complexity
mozilla
5.0
2005-05-02 CVE-2005-0144 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.
network
high complexity
mozilla
2.6
2005-05-02 CVE-2005-0142 Unspecified vulnerability in Mozilla Firefox, Mozilla and Thunderbird
Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g.
local
low complexity
mozilla
2.1
2005-05-02 CVE-2005-0141 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "with a custom getter and toString method" that are middle-clicked by the user to be opened in a new tab.
network
high complexity
mozilla
2.6
2005-03-25 CVE-2005-0592 Remote vulnerability in Mozilla Suite
Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.
network
low complexity
mozilla
7.5
2005-03-25 CVE-2005-0587 Link Following vulnerability in Mozilla
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.
network
low complexity
mozilla CWE-59
6.5
2005-03-25 CVE-2005-0585 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.
network
high complexity
mozilla
2.6
2005-03-23 CVE-2005-0143 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.
network
high complexity
mozilla
2.6
2005-03-04 CVE-2005-0593 Remote vulnerability in Mozilla Suite
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.
network
high complexity
mozilla
2.6