Show filters
48 Total Results
Displaying 41-48 of 48
Sort by:
Attacker Value
Unknown

CVE-2004-1380

Disclosure Date: October 20, 2004 (last updated February 22, 2025)
Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows and facilitate phishing attacks, aka the "Dialog Box Spoofing Vulnerability."
0
Attacker Value
Unknown

CVE-2004-1613

Disclosure Date: October 18, 2004 (last updated February 22, 2025)
Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.
0
Attacker Value
Unknown

CVE-2004-1614

Disclosure Date: October 18, 2004 (last updated February 22, 2025)
Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an "unusual combination of visual elements," including several large MARQUEE tags with large height parameters, as demonstrated by mangleme.
0
Attacker Value
Unknown

CVE-2004-0905

Disclosure Date: September 14, 2004 (last updated February 22, 2025)
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
0
Attacker Value
Unknown

CVE-2003-0594

Disclosure Date: April 15, 2004 (last updated February 22, 2025)
Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.
0
Attacker Value
Unknown

CVE-2004-0191

Disclosure Date: March 15, 2004 (last updated February 22, 2025)
Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.
0
Attacker Value
Unknown

CVE-2003-0298

Disclosure Date: June 16, 2003 (last updated February 22, 2025)
The IMAP Client for Mozilla 1.3 and 1.4a allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large (1) literal and possibly (2) mailbox size values that cause either integer signedness errors or integer overflow errors.
0
Attacker Value
Unknown

CVE-2003-0300

Disclosure Date: June 16, 2003 (last updated February 22, 2025)
The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.
0