Vulnerabilities > Mozilla > Mozilla

DATE CVE VULNERABILITY TITLE RISK
2004-08-18 CVE-2004-0761 Unspecified vulnerability in Mozilla Firefox, Mozilla and Thunderbird
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted.
network
low complexity
mozilla
5.0
2004-08-18 CVE-2004-0760 Multiple vulnerability Fixed in SCO OpenServer Release 5.0.7 Maintenance Pack 4 Released -
Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI.
network
low complexity
mozilla
6.4
2004-08-18 CVE-2004-0759 Multiple vulnerability Fixed in SCO OpenServer Release 5.0.7 Maintenance Pack 4 Released -
Mozilla before 1.7 allows remote web servers to read arbitrary files via Javascript that sets the value of an <input type="file"> tag.
network
low complexity
mozilla
6.4
2004-08-18 CVE-2004-0758 Multiple vulnerability Fixed in SCO OpenServer Release 5.0.7 Maintenance Pack 4 Released -
Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allows remote attackers to cause a denial of service to SSL pages because the malicious certificate is treated as invalid.
network
low complexity
mozilla
5.0
2004-08-18 CVE-2004-0757 Unspecified vulnerability in Mozilla Firefox, Mozilla and Thunderbird
Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code.
network
low complexity
mozilla
critical
10.0
2004-08-18 CVE-2004-0722 Multiple vulnerability Fixed in SCO OpenServer Release 5.0.7 Maintenance Pack 4 Released -
Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.
network
low complexity
mozilla netscape
critical
10.0
2004-08-06 CVE-2004-0648 Unspecified vulnerability in Mozilla Firefox, Mozilla and Thunderbird
Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referencing the shell: protocol.
network
low complexity
mozilla
critical
10.0
2004-07-27 CVE-2004-0718 Multiple vulnerability Fixed in SCO OpenServer Release 5.0.7 Maintenance Pack 4 Released -
The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
network
low complexity
firebirdsql mozilla netscape
7.5
2004-07-07 CVE-2004-0478 Resource Management Errors vulnerability in Mozilla
Unknown versions of Mozilla allow remote attackers to cause a denial of service (high CPU/RAM consumption) using Javascript with an infinite loop that continues to add input to a form, possibly as the result of inserting control characters, as demonstrated using an embedded ctrl-U.
network
high complexity
mozilla CWE-399
2.6
2004-04-15 CVE-2003-0594 Unspecified vulnerability in Mozilla
Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g.
network
low complexity
mozilla
7.5