Skip to main content

Vendor/product archive

mozilla / firefox CVEs

Beta · best-effort

3,285 CVEs tagged to mozilla / firefox923 Critical, 973 High, 1,311 Medium, 78 Low, 0 Unrated.

CVE-2007-1092

Published Feb 26, 2007

Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a do…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1095

Published Feb 26, 2007

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1084

Published Feb 23, 2007

Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1004

Published Feb 20, 2007

Mozilla Firefox might allow remote attackers to conduct spoofing and phishing attacks by writing to an about:blank tab and overlaying the location bar.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0981

Published Feb 16, 2007

Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0896

Published Feb 13, 2007

Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6971

Published Feb 7, 2007

Mozilla Firefox 2.0, possibly only when running on Windows, allows remote attackers to bypass the Phishing Protection mechanism by representing an IP address in (1) dotted-hex, (2…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0800

Published Feb 7, 2007

Cross-zone vulnerability in Mozilla Firefox 1.5.0.9 considers blocked popups to have an internal zone origin, which allows user-assisted remote attackers to cross zone restriction…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0801

Published Feb 7, 2007

The nsExternalAppHandler::SetUpTempFile function in Mozilla Firefox 1.5.0.9 creates temporary files with predictable filenames based on creation time, which allows remote attacker…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0802

Published Feb 7, 2007

Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "."…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6506

Published Dec 20, 2006

The "Feed Preview" feature in Mozilla Firefox 2.0 before 2.0.0.1 sends the URL of the feed when requesting favicon.ico icons, which results in a privacy leak that might allow feed…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6507

Published Dec 20, 2006

Mozilla Firefox 2.0 before 2.0.0.1 allows remote attackers to bypass Cross-Site Scripting (XSS) protection via vectors related to a Function.prototype regression error.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6585

Published Dec 15, 2006

The Extensions manager in Mozilla Firefox 2.0 does not properly populate the list of local extensions, which allows attackers to construct an extension that hides itself by findin…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6077

Published Nov 24, 2006

The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,076-3,100 of 3,285 CVEsPage 124 of 132