Vulnerabilities > Mozilla

DATE CVE VULNERABILITY TITLE RISK
2007-04-24 CVE-2007-2176 Remote Security vulnerability in Firefox
Unspecified vulnerability in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving Javascript errors.
network
low complexity
mozilla
critical
10.0
2007-04-22 CVE-2007-2162 Denial-Of-Service vulnerability in Iceweasel
(1) Mozilla Firefox 2.0.0.3 and (2) GNU IceWeasel 2.0.0.3 allow remote attackers to cause a denial of service (browser crash or system hang) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.
network
low complexity
gnu mozilla
7.8
2007-04-11 CVE-2007-1970 Remote Security vulnerability in Firefox
Mozilla Firefox does not warn the user about HTTP elements on an HTTPS page when the HTTP elements are dynamically created by a delayed document.write, which allows remote attackers to supply unauthenticated content and conduct phishing attacks.
network
low complexity
mozilla
5.0
2007-04-02 CVE-2007-1794 Remote Security vulnerability in Browser
The Javascript engine in Mozilla 1.7 and earlier on Sun Solaris 8, 9, and 10 might allow remote attackers to execute arbitrary code via vectors involving garbage collection that causes deletion of a temporary object that is still being used.
network
low complexity
sun mozilla
critical
10.0
2007-03-30 CVE-2007-1762 Security Bypass vulnerability in Mozilla Firefox 2.0.0.1/2.0.0.2/2.0.0.3
Mozilla Firefox 2.0.0.1 through 2.0.0.3 does not canonicalize URLs before checking them against the phishing site blacklist, which allows remote attackers to bypass phishing protection via multiple / (slash) characters in the URL.
network
low complexity
mozilla
5.0
2007-03-28 CVE-2007-1736 Security Bypass vulnerability in Mozilla Firefox 2.0.0.3
Mozilla Firefox 2.0.0.3 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote attackers to bypass phishing protection.
network
low complexity
mozilla
7.5
2007-03-21 CVE-2007-1562 Information Exposure vulnerability in multiple products
The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.
6.8
2007-03-10 CVE-2007-1377 Resource Exhaustion vulnerability in multiple products
AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier that begins with search= followed by many %n sequences, a different vulnerability than CVE-2006-6027 and CVE-2006-6236.
network
low complexity
adobe mozilla netscape opera CWE-400
5.0
2007-03-06 CVE-2007-1282 Integer Overflow vulnerability in Mozilla Seamonkey and Thunderbird
Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly execute arbitrary code via a text/enhanced or text/richtext e-mail message with an extremely long line.
network
redhat mozilla
critical
9.3
2007-03-06 CVE-2007-0994 Code Injection vulnerability in multiple products
A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.
6.8