CVEs (704)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical MozillaRedhat+1 more12Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+9 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict JSAPI access to the GetProperty function, which...Show more |
5Canonical DebianMozilla+2 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+10 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13...Show more |
3Canonical MozillaSuse6Firefox Linux Enterprise DesktopLinux Enterprise Server+3 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly perform a cast of an unspecified variable during use of the instanceof operator on a JavaScript object, which allows remote...Show more |
4Canonical MozillaRedhat+1 more12Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+9 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 might allow user-assisted remote attacke...Show more |
5Canonical DebianMozilla+2 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+10 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils)...Show more |
3Canonical MozillaSuse6Firefox Linux Enterprise DesktopLinux Enterprise Server+3 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by lever...Show more |
3Canonical MozillaSuse6Firefox Linux Enterprise DesktopLinux Enterprise Server+3 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has a SELECT element's menu active, which allows remote attackers to spoof page...Show more |
3Canonical MozillaSuse6Firefox Linux Enterprise DesktopLinux Enterprise Server+3 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 allow remote attackers to cause a denial of service (memory corruption and app...Show more |
5Canonical DebianMozilla+2 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+10 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remo...Show more |
1Mozilla 4Firefox SeamonkeyThunderbird+1 moreApr 29, 2026 Aug 29, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 does not properly follow the securi...Show more |
5Canonical MozillaOpensuse+2 more12Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+9 moreApr 29, 2026 Aug 29, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between different https sites, which allows remote attackers to spoo...Show more |
1Mozilla 3Firefox SeamonkeyThunderbirdApr 29, 2026 Aug 29, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 loads subresources during parsing of text/html data within an extension, which allows remote attackers to obtain...Show more |
6Canonical DebianMozilla+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreApr 29, 2026 Aug 29, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows rem...Show more |
1Mozilla 3Firefox SeamonkeyThunderbirdApr 29, 2026 Aug 29, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 Summer Institute of Linguistics (SIL) Graphite 2, as used in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12, allows remote attackers to execute arbitrary code or cause a denial of service...Show more |
1Mozilla 4Firefox SeamonkeyThunderbird+1 moreApr 29, 2026 Aug 29, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 Use-after-free vulnerability in the nsTArray_base::Length function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 al...Show more |
1Mozilla 4Firefox SeamonkeyThunderbird+1 moreApr 29, 2026 Aug 29, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer overflow in the nsSVGFEMorphologyElement::Filter function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 all...Show more |
5Canonical MozillaOpensuse+2 more14Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+11 moreApr 29, 2026 Aug 29, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 Use-after-free vulnerability in the WebGL implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remot...Show more |
5Canonical MozillaOpensuse+2 more13Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+10 moreApr 29, 2026 Aug 29, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 The WebGL implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 on Linux, when a large number of sampler uni...Show more |
1Mozilla 4Firefox SeamonkeyThunderbird+1 moreApr 29, 2026 Aug 29, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allow remote attackers to execute arbitrary code or cause a denial of se...Show more |
1Mozilla 4Firefox SeamonkeyThunderbird+1 moreApr 29, 2026 Aug 29, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 Use-after-free vulnerability in the gfxTextRun::GetUserData function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12...Show more |