Show filters
71 Total Results
Displaying 31-40 of 71
Sort by:
Attacker Value
Unknown
CVE-2007-1562
Disclosure Date: March 21, 2007 (last updated October 04, 2023)
The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.
0
Attacker Value
Unknown
CVE-2007-0780
Disclosure Date: February 26, 2007 (last updated October 04, 2023)
browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with multiple frames having the same data: URI.
0
Attacker Value
Unknown
CVE-2007-0009
Disclosure Date: February 26, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.
0
Attacker Value
Unknown
CVE-2007-0778
Disclosure Date: February 26, 2007 (last updated October 04, 2023)
The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache.
0
Attacker Value
Unknown
CVE-2007-0777
Disclosure Date: February 26, 2007 (last updated October 04, 2023)
The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption.
0
Attacker Value
Unknown
CVE-2007-0988
Disclosure Date: February 20, 2007 (last updated October 04, 2023)
The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unserializing certain integer expressions, which only cause 32-bit arguments to be used after the check for a negative value, as demonstrated by an "a:2147483649:{" argument.
0
Attacker Value
Unknown
CVE-2007-0908
Disclosure Date: February 13, 2007 (last updated October 04, 2023)
The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows context-dependent attackers to read stack memory via a wddxPacket element that contains a variable with a string name before a numerical variable.
0
Attacker Value
Unknown
CVE-2006-6811
Disclosure Date: December 29, 2006 (last updated February 08, 2024)
KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to an Internet Relay Chat (IRC) server, which causes an assertion failure and results in a NULL pointer dereference. NOTE: this issue was originally reported as a buffer overflow.
0
Attacker Value
Unknown
CVE-2006-6501
Disclosure Date: December 20, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.
0
Attacker Value
Unknown
CVE-2006-6503
Disclosure Date: December 20, 2006 (last updated October 04, 2023)
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: URI.
0