Vulnerabilities > Mozilla

DATE CVE VULNERABILITY TITLE RISK
2007-02-26 CVE-2007-0776 Buffer Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to execute arbitrary code via a large stroke-width attribute in the clipPath element in an SVG file.
network
mozilla CWE-119
critical
9.3
2007-02-26 CVE-2007-0775 Remote vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allow remote attackers to cause a denial of service (crash) and potentially execute arbitrary code via certain vectors.
local
high complexity
mozilla
3.7
2007-02-26 CVE-2007-1095 Unspecified vulnerability in Mozilla Firefox and Seamonkey
Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site that is visited by a client.
network
mozilla
6.8
2007-02-26 CVE-2007-1092 Unspecified vulnerability in Mozilla Firefox and Seamonkey
Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize hook on DOM window objects.
network
mozilla
critical
9.3
2007-02-23 CVE-2007-1084 Configuration vulnerability in Mozilla Firefox
Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of the last visited web page.
network
mozilla CWE-16
6.8
2007-02-20 CVE-2007-1004 Unspecified vulnerability in Mozilla Firefox 2.0
Mozilla Firefox might allow remote attackers to conduct spoofing and phishing attacks by writing to an about:blank tab and overlaying the location bar.
network
mozilla
4.3
2007-02-16 CVE-2007-0981 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox and Seamonkey
Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.
network
low complexity
mozilla CWE-264
7.5
2007-02-13 CVE-2007-0896 Cross-Site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than CVE-2006-4712.
network
mozilla sage CWE-79
4.3
2007-02-07 CVE-2007-0802 Improper Input Validation vulnerability in multiple products
Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist filter.
network
low complexity
mozilla opera CWE-20
6.4
2007-02-07 CVE-2007-0801 Unspecified vulnerability in Mozilla Firefox 1.5.0.9
The nsExternalAppHandler::SetUpTempFile function in Mozilla Firefox 1.5.0.9 creates temporary files with predictable filenames based on creation time, which allows remote attackers to execute arbitrary web script or HTML via a crafted XMLHttpRequest.
network
mozilla
4.3