Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown

CVE-2004-0191

Disclosure Date: March 15, 2004 (last updated February 22, 2025)
Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.
0
Attacker Value
Unknown

CVE-2002-2338

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message.
0
Attacker Value
Unknown

CVE-2002-2013

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
0
Attacker Value
Unknown

CVE-2002-1091

Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.
0
Attacker Value
Unknown

CVE-2002-1126

Disclosure Date: September 24, 2002 (last updated February 22, 2025)
Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to determine the next page that is being visited, including manually entered URLs, using the onunload handler.
0