CVEs (3,269)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-orig...Show more |
7Canonical DebianFedoraproject+4 more13Debian Linux FedoraFirefox+10 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute...Show more |
3Canonical DebianMozilla3Debian Linux FirefoxUbuntu LinuxApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaSc...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via ve...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers t...Show more |
1Mozilla 3Firefox SeamonkeyThunderbirdApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The layout engine in Mozilla Firefox 3.x before 3.0.4, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via multiple vectors that trigger an as...Show more |
Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrar...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly exec...Show more |
Mozilla Firefox 2.x before 2.0.0.18 and SeaMonkey 1.x before 1.1.13 do not properly check when the Flash module has been dynamically unloaded properly, which allows remote attackers to execute arbitrary code via a crafte...Show more |
1Mozilla 3Firefox SeamonkeyThunderbirdApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly change the source URI when processing a canvas element and an HTTP redirect, which allows remote attac...Show more |
3Canonical DebianMozilla4Debian Linux FirefoxSeamonkey+1 moreApr 23, 2026 Nov 13, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 3.0.1 through 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF, o...Show more |
3Canonical DebianMozilla4Debian Linux FirefoxSeamonkey+1 moreApr 23, 2026 Oct 15, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted...Show more |
The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeyd...Show more |
The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Sep 24, 2008 N/A· v4 N/A· v3 7.8 HIGH· v2 Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML fi...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Sep 24, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 on Linux allows remote attackers to read arbitrary files via a .. (dot d...Show more |
Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are...Show more |
3Canonical DebianMozilla5Debian Linux FirefoxSeamonkey+2 moreApr 23, 2026 Sep 24, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via...Show more |
Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors relate...Show more |