Show filters
52 Total Results
Displaying 31-40 of 52
Sort by:
Attacker Value
Unknown

CVE-2005-0401

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."
0
Attacker Value
Unknown

CVE-2005-1155

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a <LINK rel="icon"> tag with a javascript: URL in the href attribute, aka "Firelinking."
0
Attacker Value
Unknown

CVE-2005-0592

Disclosure Date: March 25, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.
0
Attacker Value
Unknown

CVE-2005-0585

Disclosure Date: March 25, 2005 (last updated February 22, 2025)
Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.
0
Attacker Value
Unknown

CVE-2005-0143

Disclosure Date: March 23, 2005 (last updated February 22, 2025)
Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.
0
Attacker Value
Unknown

CVE-2005-0593

Disclosure Date: March 04, 2005 (last updated February 22, 2025)
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.
0
Attacker Value
Unknown

CVE-2004-0904

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
0
Attacker Value
Unknown

CVE-2004-1451

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrusted sites and facilitate phishing attacks.
0
Attacker Value
Unknown

CVE-2004-0908

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript code to read and write to the clipboard, and possibly obtain sensitive information, via script-generated events such as Ctrl-Ins.
0
Attacker Value
Unknown

CVE-2004-1449

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determine the location of files on a user's hard drive by obscuring a file upload control and tricking the user into dragging text into that control.
0