← Back

Mozilla

mozilla

Vendor: Mozilla • 108 CVEs

CVEs (108)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Mozilla
NetscapeOpera Software
3Mozilla
NavigatorOpera Web Browser
Apr 16, 2026
Oct 4, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.
2Galeon
Mozilla
2Galeon Browser
Mozilla
Apr 16, 2026
Sep 24, 2002
N/A· v4
N/A· v3
2.6 LOW· v2
Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to determine the next p...Show more
Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to determine the next page that is being visited, including manually entered URLs, using the onunload handler.Show less
3Microsoft
MozillaNetscape
3Internet Explorer
MozillaNavigator
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malic...Show more
The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted site into one frame, and passing the information to the attacker-controlled frame, which is allowed because the document.domain of the two frames matches on the parent domain.Show less
2Mozilla
Netscape
2Mozilla
Navigator
Apr 16, 2026
Jun 25, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the...Show more
The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property.Show less
3Galeon
MozillaNetscape
3Galeon Browser
MozillaNavigator
Apr 16, 2026
Jun 18, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect.
2Mozilla
Netscape
3Communicator
MozillaNavigator
Apr 16, 2026
Jun 18, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI.
1Mozilla
1Mozilla
Apr 16, 2026
Dec 31, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.
2Mozilla
Netscape
2Communicator
Mozilla
Apr 16, 2026
Jul 25, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.