Vulnerabilities > Mozilla

DATE CVE VULNERABILITY TITLE RISK
2005-09-28 CVE-2005-3089 Remote Denial of Service vulnerability in Multiple Browser Proxy Auto-Config Script Handling
Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement.
network
high complexity
mozilla
2.6
2005-09-23 CVE-2005-2707 Unspecified vulnerability in Mozilla Firefox and Mozilla Suite
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows without user interface components such as the address and status bar, which could be used to conduct spoofing or phishing attacks.
network
low complexity
mozilla
5.0
2005-09-23 CVE-2005-2706 Unspecified vulnerability in Mozilla Firefox and Mozilla Suite
Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.
network
low complexity
mozilla
6.4
2005-09-23 CVE-2005-2705 Integer Overflow vulnerability in Mozilla Browser/Firefox JavaScript Engine
Integer overflow in the JavaScript engine in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 might allow remote attackers to execute arbitrary code.
network
low complexity
mozilla
7.5
2005-09-23 CVE-2005-2704 Unspecified vulnerability in Mozilla Firefox and Mozilla Suite
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface.
network
low complexity
mozilla
5.0
2005-09-23 CVE-2005-2703 Code Injection vulnerability in Mozilla Firefox and Mozilla Suite
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.
network
low complexity
mozilla CWE-94
5.0
2005-09-23 CVE-2005-2702 Unspecified vulnerability in Mozilla Firefox and Mozilla Suite
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters.
network
low complexity
mozilla
7.5
2005-09-23 CVE-2005-2701 Heap Overflow vulnerability in Mozilla Browser/Firefox XBM Image Processing
Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.
network
low complexity
mozilla
7.5
2005-09-20 CVE-2005-2968 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.
network
low complexity
mozilla
7.5
2005-09-09 CVE-2005-2871 Remote Buffer Overflow vulnerability in Mozilla/Netscape/Firefox Browsers Domain Name
Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.
network
low complexity
mozilla
7.5