Vulnerabilities > Mozilla

DATE CVE VULNERABILITY TITLE RISK
2005-11-29 CVE-2005-3896 Unspecified vulnerability in Mozilla
Mozilla allows remote attackers to cause a denial of service (CPU consumption) via a Javascript BODY onload event that calls the window function.
network
low complexity
mozilla
7.8
2005-11-01 CVE-2005-3402 Unspecified vulnerability in Mozilla Thunderbird 1.0.5/1.0.7
The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authentication information without detection via a man-in-the-middle (MITM) attack that bypasses TLS authentication or downgrades CRAM-MD5 authentication to plain authentication.
network
high complexity
mozilla
2.6
2005-10-05 CVE-2005-3139 Information Disclosure vulnerability in Bugzilla User-Matching
Bugzilla 2.19.1 through 2.20rc2 and 2.21, with user matching turned on in substring mode, allows attackers to list all users whose names match an arbitrary substring, even when the usevisibilitygroups parameter is set.
network
low complexity
mozilla
5.0
2005-10-05 CVE-2005-3138 Information Disclosure vulnerability in Bugzilla config.cgi
Bugzilla 2.18rc1 through 2.18.3, 2.19 through 2.20rc2, and 2.21 allows remote attackers to obtain sensitive information such as the list of installed products via the config.cgi file, which is accessible even when the requirelogin parameter is set.
network
low complexity
mozilla
5.0
2005-09-28 CVE-2005-3089 Remote Denial of Service vulnerability in Multiple Browser Proxy Auto-Config Script Handling
Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement.
network
high complexity
mozilla
2.6
2005-09-23 CVE-2005-2707 Unspecified vulnerability in Mozilla Firefox and Mozilla Suite
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows without user interface components such as the address and status bar, which could be used to conduct spoofing or phishing attacks.
network
low complexity
mozilla
5.0
2005-09-23 CVE-2005-2706 Unspecified vulnerability in Mozilla Firefox and Mozilla Suite
Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.
network
low complexity
mozilla
6.4
2005-09-23 CVE-2005-2705 Integer Overflow vulnerability in Mozilla Browser/Firefox JavaScript Engine
Integer overflow in the JavaScript engine in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 might allow remote attackers to execute arbitrary code.
network
low complexity
mozilla
7.5
2005-09-23 CVE-2005-2704 Unspecified vulnerability in Mozilla Firefox and Mozilla Suite
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface.
network
low complexity
mozilla
5.0
2005-09-23 CVE-2005-2703 Code Injection vulnerability in Mozilla Firefox and Mozilla Suite
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.
network
low complexity
mozilla CWE-94
5.0