Show filters
141 Total Results
Displaying 21-30 of 141
Sort by:
Attacker Value
Unknown

CVE-2012-4203

Disclosure Date: November 21, 2012 (last updated October 05, 2023)
The New Tab page in Mozilla Firefox before 17.0 uses a privileged context for execution of JavaScript code by bookmarklets, which allows user-assisted remote attackers to run arbitrary programs by leveraging a javascript: URL in a bookmark.
0
Attacker Value
Unknown

CVE-2012-4206

Disclosure Date: November 21, 2012 (last updated October 22, 2024)
Untrusted search path vulnerability in the installer in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 on Windows allows local users to gain privileges via a Trojan horse DLL in the default downloads directory.
0
Attacker Value
Unknown

CVE-2012-4210

Disclosure Date: November 21, 2012 (last updated October 22, 2024)
The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 does not properly restrict the context of HTML markup and Cascading Style Sheets (CSS) token sequences, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted stylesheet.
0
Attacker Value
Unknown

CVE-2012-5837

Disclosure Date: November 21, 2012 (last updated October 05, 2023)
The Web Developer Toolbar in Mozilla Firefox before 17.0 executes script with chrome privileges, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
0
Attacker Value
Unknown

CVE-2012-4190

Disclosure Date: October 12, 2012 (last updated October 05, 2023)
The FT2FontEntry::CreateFontEntry function in FreeType, as used in the Android build of Mozilla Firefox before 16.0.1 on CyanogenMod 10, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-3987

Disclosure Date: October 10, 2012 (last updated October 05, 2023)
Mozilla Firefox before 16.0 on Android assigns chrome privileges to Reader Mode pages, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site.
0
Attacker Value
Unknown

CVE-2012-3993

Disclosure Date: October 10, 2012 (last updated October 22, 2024)
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not properly interact with failures of InstallTrigger methods, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site, related to an "XrayWrapper pollution" issue.
0
Attacker Value
Unknown

CVE-2012-3980

Disclosure Date: August 29, 2012 (last updated October 22, 2024)
The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that injects this code and triggers an eval operation.
0
Attacker Value
Unknown

CVE-2012-3969

Disclosure Date: August 29, 2012 (last updated October 22, 2024)
Integer overflow in the nsSVGFEMorphologyElement::Filter function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via a crafted SVG filter that triggers an incorrect sum calculation, leading to a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2012-1971

Disclosure Date: August 29, 2012 (last updated October 05, 2023)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to garbage collection after certain MethodJIT execution, and unknown other vectors.
0