Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2004-1160

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Netscape 7.x to 7.2, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
0
Attacker Value
Unknown

CVE-2004-0904

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
0
Attacker Value
Unknown

CVE-2004-0905

Disclosure Date: September 14, 2004 (last updated February 22, 2025)
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
0
Attacker Value
Unknown

CVE-2004-0722

Disclosure Date: August 18, 2004 (last updated February 22, 2025)
Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2003-1265

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users select the 'Empty Trash' option, which could allow local users to access deleted messages.
0
Attacker Value
Unknown

CVE-2003-1492

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end.
0
Attacker Value
Unknown

CVE-2003-1419

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.
0
Attacker Value
Unknown

CVE-2003-0553

Disclosure Date: August 18, 2003 (last updated February 22, 2025)
Buffer overflow in the Client Detection Tool (CDT) plugin (npcdt.dll) for Netscape 7.02 allows remote attackers to execute arbitrary code via an attachment with a long filename.
0
Attacker Value
Unknown

CVE-2002-1308

Disclosure Date: November 29, 2002 (last updated February 22, 2025)
Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression.
0