← Back

Mozilla

mozilla

3,720 CVEs • 44 products

Products (44)

Click to collapse
Toggle
Firefox
firefox
Thunderbird
thunderbird
Seamonkey
seamonkey
Firefox Esr
firefox_esr
Bugzilla
bugzilla
Mozilla
mozilla
Mozilla Suite
mozilla_suite
Firefox Focus
firefox_focus
Focus
focus
Firefox Os
firefox_os
Nss
nss
Bleach
bleach
Bonsai
bonsai
Camino
camino
Vpn
vpn
Convict
convict
Nunjucks
nunjucks
Mozjpeg
mozjpeg
Pollbot
pollbot
Geckodriver
geckodriver
Gecko
gecko
Geckb
geckb
Libxul
libxul
Zamboni
zamboni
Firefoxos
firefoxos
Persona
persona
Hubs Cloud
hubs_cloud
Mozilla Vpn
mozilla_vpn
Nss Esr
nss_esr
Hawk
hawk
Common Voice
common_voice
Sccache
sccache
Neqo
neqo
Rhino
rhino
0din Scanner
0din_scanner
Thin Vec
thin-vec
Klar
klar

CVEs (3,720)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mozilla
1Mozilla
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which causes the host/path check to fail.
1Mozilla
1Bugzilla
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the quips feature in Mozilla Bugzilla 2.10 through 2.17 allows remote attackers to inject arbitrary web script or HTML via the "show all quips" page.
2Mozilla
Netscape
2Mozilla
Navigator
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values and an 8-bit or 16-b...Show more
Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values and an 8-bit or 16-bit alpha channel.Show less
2Mozilla
Netscape
3Communicator
MozillaNavigator
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
2Mozilla
Netscape
2Mozilla
Navigator
Apr 16, 2026
Nov 29, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression.
1Mozilla
1Bugzilla
Apr 16, 2026
Oct 28, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to execute arbitrary SQL via a SQL injection attack.
1Mozilla
1Bugzilla
Apr 16, 2026
Oct 28, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
bugzilla_email_append.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote attackers to execute arbitrary code via shell metacharacters in a system call to processmail.
1Mozilla
1Bugzilla
Apr 16, 2026
Oct 28, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, whi...Show more
editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits.Show less
3Mozilla
NetscapeOpera Software
3Mozilla
NavigatorOpera Web Browser
Apr 16, 2026
Oct 4, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.
2Galeon
Mozilla
2Galeon Browser
Mozilla
Apr 16, 2026
Sep 24, 2002
N/A· v4
N/A· v3
2.6 LOW· v2
Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to determine the next p...Show more
Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to determine the next page that is being visited, including manually entered URLs, using the onunload handler.Show less
3Microsoft
MozillaNetscape
3Internet Explorer
MozillaNavigator
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malic...Show more
The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted site into one frame, and passing the information to the attacker-controlled frame, which is allowed because the document.domain of the two frames matches on the parent domain.Show less
1Mozilla
1Bugzilla
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL injection attack on the sort order parameter to buglist.cgi.
1Mozilla
1Bugzilla
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails.
1Mozilla
1Bugzilla
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of...Show more
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names.Show less
1Mozilla
1Bugzilla
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groupset of all bugs to the groupset of the first bug, which could inadvertently cause insecure groupset permissions to be ass...Show more
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groupset of all bugs to the groupset of the first bug, which could inadvertently cause insecure groupset permissions to be assigned to some bugs.Show less
1Mozilla
1Bugzilla
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not prope...Show more
Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi.Show less
1Mozilla
1Bugzilla
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
2.1 LOW· v2
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows authenticated users with editing privileges to delete other users by directly calling the editusers.cgi script with the "del" option.
1Mozilla
1Bugzilla
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writable permissions, and (2) creates the params file with world-writable permissions, which allows local users to modify the f...Show more
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writable permissions, and (2) creates the params file with world-writable permissions, which allows local users to modify the files and execute code.Show less
1Mozilla
1Bugzilla
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when configured to perform reverse DNS lookups, allows remote attackers to bypass IP restrictions by connecting from a system with a spoofed reverse DNS hostname.
1Mozilla
1Bugzilla
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request to queryhelp.cgi.