Show filters
146 Total Results
Displaying 141-146 of 146
Sort by:
Attacker Value
Unknown
CVE-2004-0904
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
0
Attacker Value
Unknown
CVE-2004-0908
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript code to read and write to the clipboard, and possibly obtain sensitive information, via script-generated events such as Ctrl-Ins.
0
Attacker Value
Unknown
CVE-2004-1449
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determine the location of files on a user's hard drive by obscuring a file upload control and tricking the user into dragging text into that control.
0
Attacker Value
Unknown
CVE-2004-0907
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The Linux install .tar.gz archives for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8, create certain files with insecure permissions, which could allow local users to overwrite those files and execute arbitrary code.
0
Attacker Value
Unknown
CVE-2004-0909
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 may allow remote attackers to trick users into performing unexpected actions, including installing software, via signed scripts that request enhanced abilities using the enablePrivilege parameter, then modify the meaning of certain security-relevant dialog messages.
0
Attacker Value
Unknown
CVE-2004-0906
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The XPInstall installer in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 sets insecure permissions for certain installed files within xpi packages, which could allow local users to overwrite arbitrary files or execute arbitrary code.
0