Show filters
192 Total Results
Displaying 181-190 of 192
Sort by:
Attacker Value
Unknown
CVE-2005-0752
Disclosure Date: April 18, 2005 (last updated February 22, 2025)
The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE attribute of an EMBED tag.
0
Attacker Value
Unknown
CVE-2005-0592
Disclosure Date: March 25, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.
0
Attacker Value
Unknown
CVE-2005-0585
Disclosure Date: March 25, 2005 (last updated February 22, 2025)
Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.
0
Attacker Value
Unknown
CVE-2005-0143
Disclosure Date: March 23, 2005 (last updated February 22, 2025)
Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.
0
Attacker Value
Unknown
CVE-2005-0593
Disclosure Date: March 04, 2005 (last updated February 22, 2025)
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.
0
Attacker Value
Unknown
CVE-2005-0145
Disclosure Date: January 24, 2005 (last updated February 22, 2025)
Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.
0
Attacker Value
Unknown
CVE-2004-2225
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button.
0
Attacker Value
Unknown
CVE-2004-1156
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
0
Attacker Value
Unknown
CVE-2004-1200
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.
0
Attacker Value
Unknown
CVE-2004-2227
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions.
0