Skip to main content

Vendor/product archive

mozilla / firefox CVEs

Beta · best-effort

3,295 CVEs tagged to mozilla / firefox925 Critical, 980 High, 1,312 Medium, 78 Low, 0 Unrated.

CVE-2005-0588

Published May 2, 2005

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0589

Published May 2, 2005

The Form Fill feature in Firefox before 1.0.1 allows remote attackers to steal potentially sensitive information via an input control that monitors the values that are generated b…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0591

Published May 2, 2005

Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-1153

Published May 2, 2005

Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a popup, allows remote attackers to execute arbitrary code via a javascript: URL that is executed when the user…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1154

Published May 2, 2005

Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary script in other domains via a setter function for a variable in the target domain,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1155

Published May 2, 2005

The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a <LINK rel="icon"> tag with a javascript: U…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1158

Published May 2, 2005

Multiple "missing security checks" in Firefox before 1.0.3 allow remote attackers to inject arbitrary Javascript into privileged pages using the _search target of the Firefox side…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1159

Published May 2, 2005

The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1160

Published May 2, 2005

The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DO…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0752

Published Apr 18, 2005

The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE attribute of an EMBED tag.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0585

Published Mar 25, 2005

Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0587

Published Mar 25, 2005

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0592

Published Mar 25, 2005

Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0143

Published Mar 23, 2005

Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0593

Published Mar 4, 2005

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the loc…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0231

Published Feb 7, 2005

Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0145

Published Jan 24, 2005

Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download pro…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1156

Published Dec 31, 2004

Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1200

Published Dec 31, 2004

Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously create…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,251-3,275 of 3,295 CVEsPage 131 of 132