CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Mozilla3Firefox SeamonkeyUbuntu LinuxApr 23, 2026 Dec 17, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service via vectors that trigger an assertion failure. |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Dec 17, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) and possibly tr...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attacke...Show more |
3Canonical DebianMozilla4Debian Linux FirefoxSeamonkey+1 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-orig...Show more |
7Canonical DebianFedoraproject+4 more13Debian Linux FedoraFirefox+10 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute...Show more |
3Canonical DebianMozilla3Debian Linux FirefoxUbuntu LinuxApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaSc...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via ve...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers t...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly exec...Show more |
3Canonical DebianMozilla4Debian Linux FirefoxSeamonkey+1 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers...Show more |
6Canonical DebianFedoraproject+3 more7Debian Linux FedoraGnutls+4 moreApr 23, 2026 Nov 13, 2008 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 23, 2026 Nov 5, 2008 N/A· v4 N/A· v3 7.8 HIGH· v2 The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to ca...Show more |
3Canonical DebianMozilla4Debian Linux FirefoxSeamonkey+1 moreApr 23, 2026 Oct 15, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted...Show more |
4Canonical DovecotFedoraproject+1 more4Dovecot FedoraOpensuse+1 moreApr 23, 2026 Oct 15, 2008 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions. |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Sep 24, 2008 N/A· v4 N/A· v3 7.8 HIGH· v2 Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML fi...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Sep 24, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 on Linux allows remote attackers to read arbitrary files via a .. (dot d...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Sep 24, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxApr 23, 2026 Sep 24, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors relate...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Sep 24, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruptio...Show more |