Show filters
205 Total Results
Displaying 81-90 of 205
Sort by:
Attacker Value
Unknown

CVE-2009-3014

Disclosure Date: August 31, 2009 (last updated October 04, 2023)
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly handle javascript: URIs in HTML links within 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location HTTP response header or (2) specifying the content of a Location HTTP response header.
0
Attacker Value
Unknown

CVE-2009-2663

Disclosure Date: August 04, 2009 (last updated October 04, 2023)
libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.
0
Attacker Value
Unknown

CVE-2009-2470

Disclosure Date: August 04, 2009 (last updated October 04, 2023)
Mozilla Firefox before 3.0.12, and 3.5.x before 3.5.2, allows remote SOCKS5 proxy servers to cause a denial of service (data stream corruption) via a long domain name in a reply.
0
Attacker Value
Unknown

CVE-2009-2664

Disclosure Date: August 04, 2009 (last updated October 04, 2023)
The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial of service (assertion failure and application exit) or possibly execute arbitrary code via a crafted .js file, related to a "memory safety bug." NOTE: this was originally reported as affecting versions before 3.0.13.
0
Attacker Value
Unknown

CVE-2009-2654

Disclosure Date: August 03, 2009 (last updated October 04, 2023)
Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.
0
Attacker Value
Unknown

CVE-2009-2469

Disclosure Date: July 22, 2009 (last updated October 04, 2023)
Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted document, related to a certain pointer misinterpretation.
0
Attacker Value
Unknown

CVE-2009-2466

Disclosure Date: July 22, 2009 (last updated October 04, 2023)
The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.
0
Attacker Value
Unknown

CVE-2009-2465

Disclosure Date: July 22, 2009 (last updated October 04, 2023)
Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving double frame construction, related to (1) nsHTMLContentSink.cpp, (2) nsXMLContentSink.cpp, and (3) nsPresShell.cpp, and the nsSubDocumentFrame::Reflow function.
0
Attacker Value
Unknown

CVE-2009-2471

Disclosure Date: July 22, 2009 (last updated October 04, 2023)
The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.
0
Attacker Value
Unknown

CVE-2009-2467

Disclosure Date: July 22, 2009 (last updated October 04, 2023)
Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a Flash object, a slow script dialog, and the unloading of the Flash plugin, which triggers attempted use of a deleted object.
0