Mozilla
mozilla
3,567 CVEs • 43 products
Products (43)
Click to collapseToggle
Products (43)
Click to collapse
CVEs (3,567)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Mozilla 4Firefox SeamonkeyThunderbird+1 moreApr 29, 2026 Jun 5, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Content Security Policy (CSP) implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not b...Show more |
1Mozilla 3Firefox SeamonkeyThunderbirdApr 29, 2026 Jun 5, 2012 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Untrusted search path vulnerability in Updater.exe in the Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allows local users to gain privileges via a Trojan horse wsock32.d...Show more |
The Mozilla Updater and Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allow local users to gain privileges by loading a DLL file in a privileged context. |
1Mozilla 4Firefox SeamonkeyThunderbird+1 moreApr 29, 2026 Jun 5, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in the nsHTMLReflowState::CalculateHypotheticalBox function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5...Show more |
1Mozilla 4Firefox SeamonkeyThunderbird+1 moreApr 29, 2026 Jun 5, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey be...Show more |
jsinfer.cpp in Mozilla Firefox ESR 10.x before 10.0.5 and Thunderbird ESR 10.x before 10.0.5 does not properly determine data types, which allows remote attackers to cause a denial of service (memory corruption and appli...Show more |
4Mozilla OpensuseRedhat+1 more13Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+10 moreApr 29, 2026 Jun 5, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 13.0, Thunderbird before 13.0, and SeaMonkey before 2.10 allow remote attackers to cause a denial of service (memory corruption and app...Show more |
1Mozilla 4Firefox SeamonkeyThunderbird+1 moreApr 29, 2026 Jun 5, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10...Show more |
1Mozilla 5Firefox Network Security ServicesSeamonkey+2 moreApr 29, 2026 Jun 5, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x...Show more |
3Google MozillaOpensuse5Chrome FirefoxOpensuse+2 moreApr 29, 2026 May 1, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used in Mozilla Firefox before 38.0 and other products, does not properly validate messages, which has unspecified impact and...Show more |
template/en/default/list/list.js.tmpl in Bugzilla 2.x and 3.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1 does not properly handle multiple logins, which allows remote attackers to conduc...Show more |
Bugzilla 3.5.x and 3.6.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1, when the inbound_proxies option is enabled, does not properly validate the X-Forwarded-For HTTP header, which allows...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted font. |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |