Show filters
282 Total Results
Displaying 271-280 of 282
Sort by:
Attacker Value
Unknown
CVE-2007-5959
Disclosure Date: November 26, 2007 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger memory corruption.
0
Attacker Value
Unknown
CVE-2007-5947
Disclosure Date: November 14, 2007 (last updated October 04, 2023)
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.
0
Attacker Value
Unknown
CVE-2007-4879
Disclosure Date: September 13, 2007 (last updated October 04, 2023)
Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates with minimal user interaction, and automatically sends these certificates when requested, which makes it easier for remote web sites to track user activities across domains by requesting the TLS client certificates from other domains.
0
Attacker Value
Unknown
CVE-2007-3735
Disclosure Date: July 18, 2007 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to cause a denial of service (crash) via unspecified vectors that trigger memory corruption.
0
Attacker Value
Unknown
CVE-2007-3734
Disclosure Date: July 18, 2007 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to cause a denial of service (crash) via unspecified vectors that trigger memory corruption.
0
Attacker Value
Unknown
CVE-2007-3737
Disclosure Date: July 18, 2007 (last updated October 04, 2023)
Mozilla Firefox before 2.0.0.5 allows remote attackers to execute arbitrary code with chrome privileges by calling an event handler from an unspecified "element outside of a document."
0
Attacker Value
Unknown
CVE-2007-3736
Disclosure Date: July 18, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed.
0
Attacker Value
Unknown
CVE-2007-3738
Disclosure Date: July 18, 2007 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.
0
Attacker Value
Unknown
CVE-2007-3657
Disclosure Date: July 10, 2007 (last updated November 08, 2023)
Mozilla Firefox 2.0.0.4 allows remote attackers to cause a denial of service by opening multiple tabs in a popup window. NOTE: this issue has been disputed by third party researchers, stating that "this does not crash on me, and I can't see a likely mechanism of action that would lead to a DoS condition.
0
Attacker Value
Unknown
CVE-2007-3511
Disclosure Date: July 03, 2007 (last updated October 04, 2023)
The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.
0