Show filters
288 Total Results
Displaying 271-280 of 288
Sort by:
Attacker Value
Unknown
CVE-2006-1736
Disclosure Date: April 14, 2006 (last updated October 04, 2023)
Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to trick users into downloading and saving an executable file via an image that is overlaid by a transparent image link that points to the executable, which causes the executable to be saved when the user clicks the "Save image as..." option. NOTE: this attack is made easier due to a GUI truncation issue that prevents the user from seeing the malicious extension when there is extra whitespace in the filename.
0
Attacker Value
Unknown
CVE-2006-1730
Disclosure Date: April 14, 2006 (last updated October 04, 2023)
Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via a large number in the CSS letter-spacing property that leads to a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2006-1045
Disclosure Date: March 07, 2006 (last updated February 22, 2025)
The HTML rendering engine in Mozilla Thunderbird 1.5, when "Block loading of remote images in mail messages" is enabled, does not properly block external images from inline HTML attachments, which could allow remote attackers to obtain sensitive information, such as application version or IP address, when the user reads the email and the external image is accessed.
0
Attacker Value
Unknown
CVE-2006-0836
Disclosure Date: February 22, 2006 (last updated February 22, 2025)
Mozilla Thunderbird 1.5 allows user-assisted attackers to cause an unspecified denial of service by tricking the user into importing an LDIF file with a long field into the address book, as demonstrated by a long homePhone field.
0
Attacker Value
Unknown
CVE-2006-0299
Disclosure Date: February 02, 2006 (last updated February 22, 2025)
The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.
0
Attacker Value
Unknown
CVE-2006-0297
Disclosure Date: February 02, 2006 (last updated February 22, 2025)
Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.
0
Attacker Value
Unknown
CVE-2006-0294
Disclosure Date: February 02, 2006 (last updated February 22, 2025)
Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.
0
Attacker Value
Unknown
CVE-2006-0295
Disclosure Date: February 02, 2006 (last updated February 22, 2025)
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.
0
Attacker Value
Unknown
CVE-2006-0236
Disclosure Date: January 18, 2006 (last updated February 22, 2025)
GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large number of spaces ending with a dangerous extension that is not displayed by Thunderbird, along with an inconsistent Content-Type header, which could be used to trick a user into downloading dangerous content by dragging or saving the attachment.
0
Attacker Value
Unknown
CVE-2005-2353
Disclosure Date: August 05, 2005 (last updated February 22, 2025)
run-mozilla.sh in Thunderbird, with debugging enabled, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
0