CVEs (3,269)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Status Bar Obfuscation" and "Cl...Show more |
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser ses...Show more |
Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) re...Show more |
Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long string value for the hash property (aka location.hash). NOTE: it was later r...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Dec 17, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote attackers to bypass the same origin policy, inject content into documents associated with...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Dec 17, 2008 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to run arbitrary JavaScript with c...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Dec 17, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and conduct cross-site scripting (XSS) a...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Dec 17, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Dec 17, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse URLs with leading whitespace or control characters, which might allow rem...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Dec 17, 2008 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Dec 17, 2008 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy by causing the browser to issue an XMLHt...Show more |
Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entities that are similar to cookies. |
Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836. |
The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allo...Show more |
2Canonical Mozilla3Firefox SeamonkeyUbuntu LinuxApr 23, 2026 Dec 17, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corrupt...Show more |
2Canonical Mozilla3Firefox SeamonkeyUbuntu LinuxApr 23, 2026 Dec 17, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service via vectors that trigger an assertion failure. |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Dec 17, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) and possibly tr...Show more |
1Mozilla 3Firefox SeamonkeyThunderbirdApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (cr...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attacke...Show more |
3Canonical DebianMozilla4Debian Linux FirefoxSeamonkey+1 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding...Show more |