Show filters
81 Total Results
Displaying 61-70 of 81
Sort by:
Attacker Value
Unknown

CVE-2005-0592

Disclosure Date: March 25, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.
0
Attacker Value
Unknown

CVE-2005-0585

Disclosure Date: March 25, 2005 (last updated February 22, 2025)
Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.
0
Attacker Value
Unknown

CVE-2005-0143

Disclosure Date: March 23, 2005 (last updated February 22, 2025)
Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.
0
Attacker Value
Unknown

CVE-2005-0593

Disclosure Date: March 04, 2005 (last updated February 22, 2025)
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.
0
Attacker Value
Unknown

CVE-2005-0149

Disclosure Date: February 15, 2005 (last updated February 22, 2025)
Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail messages.
0
Attacker Value
Unknown

CVE-2004-0902

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII hostname.
0
Attacker Value
Unknown

CVE-2004-0903

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.
0
Attacker Value
Unknown

CVE-2004-0904

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
0
Attacker Value
Unknown

CVE-2004-0908

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript code to read and write to the clipboard, and possibly obtain sensitive information, via script-generated events such as Ctrl-Ins.
0
Attacker Value
Unknown

CVE-2004-1753

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs.
0