Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2004-0191
Disclosure Date: March 15, 2004 (last updated February 22, 2025)
Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.
0
Attacker Value
Unknown
CVE-2002-2338
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message.
0
Attacker Value
Unknown
CVE-2002-2013
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
0
Attacker Value
Unknown
CVE-2002-1308
Disclosure Date: November 29, 2002 (last updated February 22, 2025)
Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression.
0
Attacker Value
Unknown
CVE-2002-1091
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.
0
Attacker Value
Unknown
CVE-2002-1126
Disclosure Date: September 24, 2002 (last updated February 22, 2025)
Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to determine the next page that is being visited, including manually entered URLs, using the onunload handler.
0
Attacker Value
Unknown
CVE-2001-1490
Disclosure Date: December 31, 2001 (last updated February 22, 2025)
Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.
0