Vulnerabilities > Mozilla > Mozilla

DATE CVE VULNERABILITY TITLE RISK
2004-03-15 CVE-2004-0191 Cross-Site Scripting vulnerability in Mozilla Browser Zombie Document
Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.
network
mozilla
6.8
2003-12-31 CVE-2003-1265 Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users select the 'Empty Trash' option, which could allow local users to access deleted messages.
local
low complexity
mozilla netscape
2.1
2003-10-07 CVE-2003-0791 Deserialization of Untrusted Data vulnerability in multiple products
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.
network
low complexity
mozilla sco CWE-502
critical
9.8
2003-06-16 CVE-2003-0300 Denial-Of-Service vulnerability in Pine
The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.
5.0
2003-06-16 CVE-2003-0298 Denial-Of-Service vulnerability in Browser
The IMAP Client for Mozilla 1.3 and 1.4a allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large (1) literal and possibly (2) mailbox size values that cause either integer signedness errors or integer overflow errors.
network
low complexity
mozilla
7.5
2002-12-31 CVE-2002-2359 Cross-Site Scripting vulnerability in Mozilla 1.0/1.1
Cross-site scripting (XSS) vulnerability in the FTP view feature in Mozilla 1.0 allows remote attackers to inject arbitrary web script or HTML via the title tag of an ftp URL.
network
mozilla CWE-79
4.3
2002-12-31 CVE-2002-2338 Improper Input Validation vulnerability in multiple products
The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message.
network
low complexity
mozilla netscape CWE-20
5.0
2002-12-31 CVE-2002-2314 Improper Input Validation vulnerability in Mozilla 1.0
Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which causes the host/path check to fail.
network
low complexity
mozilla CWE-20
5.0
2002-12-31 CVE-2002-2061 Denial-Of-Service vulnerability in Netscape
Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values and an 8-bit or 16-bit alpha channel.
network
low complexity
mozilla netscape
7.5
2002-12-31 CVE-2002-2013 Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
network
low complexity
mozilla netscape
5.0