Mozilla
mozilla
3,567 CVEs • 43 products
Products (43)
Click to collapseToggle
Products (43)
Click to collapse
CVEs (3,567)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical MozillaRedhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in the nsSMILAnimationController::DoSample function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey...Show more |
5Canonical DebianMozilla+2 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+10 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in the nsHTMLEditor::IsPrevCharInNodeWhitespace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonk...Show more |
5Canonical DebianMozilla+2 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+10 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in the nsHTMLCSSUtils::CreateCSSPropertyTxn function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey...Show more |
4Canonical MozillaRedhat+1 more12Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+9 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 The IsCSSWordSpacingSpace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute...Show more |
4Canonical MozillaRedhat+1 more12Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+9 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to conduct cross-site scripting (XSS) attacks via...Show more |
1Mozilla 4Firefox SeamonkeyThunderbird+1 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not properly inte...Show more |
4Canonical MozillaRedhat+1 more12Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+9 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage history data, which allows remote attackers to co...Show more |
4Canonical MozillaRedhat+1 more12Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+9 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict JSAPI access to the GetProperty function, which...Show more |
5Canonical DebianMozilla+2 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+10 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13...Show more |
3Canonical MozillaSuse6Firefox Linux Enterprise DesktopLinux Enterprise Server+3 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly perform a cast of an unspecified variable during use of the instanceof operator on a JavaScript object, which allows remote...Show more |
4Canonical MozillaRedhat+1 more12Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+9 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 might allow user-assisted remote attacke...Show more |
Mozilla Firefox before 16.0 on Android assigns chrome privileges to Reader Mode pages, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site. |
5Canonical DebianMozilla+2 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+10 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils)...Show more |
3Canonical MozillaSuse6Firefox Linux Enterprise DesktopLinux Enterprise Server+3 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by lever...Show more |
3Canonical MozillaSuse6Firefox Linux Enterprise DesktopLinux Enterprise Server+3 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has a SELECT element's menu active, which allows remote attackers to spoof page...Show more |
3Canonical MozillaSuse6Firefox Linux Enterprise DesktopLinux Enterprise Server+3 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 allow remote attackers to cause a denial of service (memory corruption and app...Show more |
5Canonical DebianMozilla+2 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+10 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remo...Show more |
The SPDY protocol 3 and earlier, as used in Mozilla Firefox, Google Chrome, and other products, can perform TLS encryption of compressed data without properly obfuscating the length of the unencrypted data, which allows...Show more |
3Debian GoogleMozilla3Chrome Debian LinuxFirefoxApr 29, 2026 Sep 15, 2012 N/A· v4 N/A· v3 2.6 LOW· v2 The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-mi...Show more |
Bugzilla 2.x and 3.x through 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 stores potentially sensitive information under the web root with insufficient access control, which...Show more |