Vulnerabilities > Mozilla > Mozilla > 1.7
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2005-02-15 | CVE-2005-0149 | Unspecified vulnerability in Mozilla and Thunderbird Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail messages. | 5.0 |
2005-02-08 | CVE-2005-0233 | The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks. | 7.5 |
2005-01-27 | CVE-2004-0903 | Remote Buffer Overflow vulnerability in Mozilla Browser Vcard Handling Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message. | 10.0 |
2005-01-27 | CVE-2004-0902 | Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII hostname. | 10.0 |
2004-12-31 | CVE-2004-1450 | Remote Security vulnerability in Mozilla 1.7 Unknown vulnerability in LiveConnect in Mozilla 1.7 beta allows remote attackers to read arbitrary files in known locations. | 5.0 |
2004-12-31 | CVE-2004-1156 | Unspecified vulnerability in Mozilla Firefox and Mozilla Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. network mozilla | 4.3 |
2004-12-31 | CVE-2004-0909 | Unspecified vulnerability in Mozilla and Thunderbird Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 may allow remote attackers to trick users into performing unexpected actions, including installing software, via signed scripts that request enhanced abilities using the enablePrivilege parameter, then modify the meaning of certain security-relevant dialog messages. | 5.1 |
2004-12-31 | CVE-2004-0908 | Unspecified vulnerability in Mozilla and Thunderbird Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript code to read and write to the clipboard, and possibly obtain sensitive information, via script-generated events such as Ctrl-Ins. | 4.0 |
2004-12-31 | CVE-2004-0907 | Unspecified vulnerability in Mozilla and Thunderbird The Linux install .tar.gz archives for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8, create certain files with insecure permissions, which could allow local users to overwrite those files and execute arbitrary code. | 4.6 |
2004-12-31 | CVE-2004-0906 | Unspecified vulnerability in Mozilla and Thunderbird The XPInstall installer in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 sets insecure permissions for certain installed files within xpi packages, which could allow local users to overwrite arbitrary files or execute arbitrary code. | 4.6 |