Show filters
57 Total Results
Displaying 31-40 of 57
Sort by:
Attacker Value
Unknown
CVE-2005-0584
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Firefox before 1.0.1 and Mozilla before 1.7.6, when displaying the HTTP Authentication dialog, do not change the focus to the tab that generated the prompt, which could facilitate spoofing and phishing attacks.
0
Attacker Value
Unknown
CVE-2005-0588
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.
0
Attacker Value
Unknown
CVE-2005-0146
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to obtain sensitive data from the clipboard via Javascript that generates a middle-click event on systems for which a middle-click performs a paste operation.
0
Attacker Value
Unknown
CVE-2005-0586
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to spoof the extensions of files to download via the Content-Disposition header, which could be used to trick users into downloading dangerous content.
0
Attacker Value
Unknown
CVE-2005-0142
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.
0
Attacker Value
Unknown
CVE-2005-0401
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."
0
Attacker Value
Unknown
CVE-2005-0238
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
0
Attacker Value
Unknown
CVE-2005-1155
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a <LINK rel="icon"> tag with a javascript: URL in the href attribute, aka "Firelinking."
0
Attacker Value
Unknown
CVE-2005-0592
Disclosure Date: March 25, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.
0
Attacker Value
Unknown
CVE-2005-0585
Disclosure Date: March 25, 2005 (last updated February 22, 2025)
Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.
0