Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown
CVE-2004-1156
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
0
Attacker Value
Unknown
CVE-2004-1613
Disclosure Date: October 18, 2004 (last updated February 22, 2025)
Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.
0
Attacker Value
Unknown
CVE-2004-1614
Disclosure Date: October 18, 2004 (last updated February 22, 2025)
Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an "unusual combination of visual elements," including several large MARQUEE tags with large height parameters, as demonstrated by mangleme.
0
Attacker Value
Unknown
CVE-2004-0905
Disclosure Date: September 14, 2004 (last updated February 22, 2025)
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
0
Attacker Value
Unknown
CVE-2003-0594
Disclosure Date: April 15, 2004 (last updated February 22, 2025)
Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.
0
Attacker Value
Unknown
CVE-2004-0191
Disclosure Date: March 15, 2004 (last updated February 22, 2025)
Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.
0
Attacker Value
Unknown
CVE-2002-2359
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the FTP view feature in Mozilla 1.0 allows remote attackers to inject arbitrary web script or HTML via the title tag of an ftp URL.
0
Attacker Value
Unknown
CVE-2002-1308
Disclosure Date: November 29, 2002 (last updated February 22, 2025)
Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression.
0
Attacker Value
Unknown
CVE-2002-1126
Disclosure Date: September 24, 2002 (last updated February 22, 2025)
Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to determine the next page that is being visited, including manually entered URLs, using the onunload handler.
0