Show filters
91 Total Results
Displaying 81-90 of 91
Sort by:
Attacker Value
Unknown
CVE-2008-4070
Disclosure Date: September 27, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long header in a news article, related to "canceling [a] newsgroup message" and "cancelled newsgroup messages."
0
Attacker Value
Unknown
CVE-2008-4060
Disclosure Date: September 24, 2008 (last updated October 04, 2023)
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2) XSLT.
0
Attacker Value
Unknown
CVE-2008-3835
Disclosure Date: September 24, 2008 (last updated October 04, 2023)
The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.
0
Attacker Value
Unknown
CVE-2005-4809
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via an A HREF tag that contains a TABLE tag that contains another A tag.
0
Attacker Value
Unknown
CVE-2005-2261
Disclosure Date: July 13, 2005 (last updated February 22, 2025)
Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.
0
Attacker Value
Unknown
CVE-2005-0255
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, which leads to heap corruption.
0
Attacker Value
Unknown
CVE-2005-0590
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.
0
Attacker Value
Unknown
CVE-2005-0399
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size.
0
Attacker Value
Unknown
CVE-2005-0142
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.
0
Attacker Value
Unknown
CVE-2005-0149
Disclosure Date: February 15, 2005 (last updated February 22, 2025)
Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail messages.
0