Show filters
243 Total Results
Displaying 221-230 of 243
Sort by:
Attacker Value
Unknown

CVE-2008-4059

Disclosure Date: September 24, 2008 (last updated October 04, 2023)
The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.
0
Attacker Value
Unknown

CVE-2008-4069

Disclosure Date: September 24, 2008 (last updated October 04, 2023)
The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted XBM image file.
0
Attacker Value
Unknown

CVE-2008-0016

Disclosure Date: September 24, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.
0
Attacker Value
Unknown

CVE-2008-3835

Disclosure Date: September 24, 2008 (last updated October 04, 2023)
The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.
0
Attacker Value
Unknown

CVE-2008-3836

Disclosure Date: September 24, 2008 (last updated October 04, 2023)
feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview and the (1) elem.doCommand, (2) elem.dispatchEvent, (3) _setTitleText, (4) _setTitleImage, and (5) _initSubscriptionUI functions.
0
Attacker Value
Unknown

CVE-2008-2933

Disclosure Date: July 17, 2008 (last updated October 04, 2023)
Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involving a series of URIs that is not entirely handled by a vector application, as exploited in conjunction with CVE-2008-2540. NOTE: this issue exists because of an insufficient fix for CVE-2005-2267.
0
Attacker Value
Unknown

CVE-2008-2809

Disclosure Date: July 08, 2008 (last updated October 04, 2023)
Mozilla 1.9 M8 and earlier, Mozilla Firefox 2 before 2.0.0.15, SeaMonkey 1.1.5 and other versions before 1.1.10, Netscape 9.0, and other Mozilla-based web browsers, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regard the certificate as also accepted for all domain names in subjectAltName:dNSName fields, which makes it easier for remote attackers to trick a user into accepting an invalid certificate for a spoofed web site.
0
Attacker Value
Unknown

CVE-2008-2798

Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors related to the layout engine.
0
Attacker Value
Unknown

CVE-2008-2807

Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .properties file for an add-on, which allows remote attackers to read uninitialized memory, as demonstrated by use of ISO 8859 encoding instead of UTF-8 encoding in a French .properties file.
0
Attacker Value
Unknown

CVE-2008-2800

Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors involving (1) an event handler attached to an outer window, (2) a SCRIPT element in an unloaded document, or (3) the onreadystatechange handler in conjunction with an XMLHttpRequest.
0