Show filters
288 Total Results
Displaying 251-260 of 288
Sort by:
Attacker Value
Unknown

CVE-2006-3807

Disclosure Date: July 27, 2006 (last updated October 04, 2023)
Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code via script that changes the standard Object() constructor to return a reference to a privileged object and calling "named JavaScript functions" that use the constructor.
0
Attacker Value
Unknown

CVE-2006-3806

Disclosure Date: July 27, 2006 (last updated October 04, 2023)
Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects; and (2) unspecified "string function arguments."
0
Attacker Value
Unknown

CVE-2006-2787

Disclosure Date: June 02, 2006 (last updated October 04, 2023)
EvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to gain privileges via javascript that calls the valueOf method on objects that were created outside of the sandbox.
0
Attacker Value
Unknown

CVE-2006-2779

Disclosure Date: June 02, 2006 (last updated October 04, 2023)
Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested <option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which leads to memory corruption.
0
Attacker Value
Unknown

CVE-2006-2775

Disclosure Date: June 02, 2006 (last updated October 04, 2023)
Mozilla Firefox and Thunderbird before 1.5.0.4 associates XUL attributes with the wrong URL under certain unspecified circumstances, which might allow remote attackers to bypass restrictions by causing a persisted string to be associated with the wrong URL.
0
Attacker Value
Unknown

CVE-2006-2776

Disclosure Date: June 02, 2006 (last updated October 04, 2023)
Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined setters on an object prototype, which allows remote attackers to execute code at a higher privilege than intended.
0
Attacker Value
Unknown

CVE-2006-1738

Disclosure Date: April 14, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) by changing the (1) -moz-grid and (2) -moz-grid-group display styles.
0
Attacker Value
Unknown

CVE-2006-1737

Disclosure Date: April 14, 2006 (last updated October 04, 2023)
Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary bytecode via JavaScript with a large regular expression.
0
Attacker Value
Unknown

CVE-2006-1731

Disclosure Date: April 14, 2006 (last updated October 04, 2023)
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown

CVE-2006-1739

Disclosure Date: April 14, 2006 (last updated October 04, 2023)
The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer overflow.
0