Search CVE reports
21 – 30 of 48 results
The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeydown,...
10 affected packages
firefox, firefox-3.0, iceape, icedove, iceweasel...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| firefox-3.0 | — | — | — | — | — |
| iceape | — | — | — | — | — |
| icedove | — | — | — | — | — |
| iceweasel | — | — | — | — | — |
| mozilla-thunderbird | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner | — | — | — | — | — |
| xulrunner-1.9 | — | — | — | — | — |
Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.
10 affected packages
firefox, firefox-3.0, iceape, icedove, iceweasel...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| firefox-3.0 | — | — | — | — | — |
| iceape | — | — | — | — | — |
| icedove | — | — | — | — | — |
| iceweasel | — | — | — | — | — |
| mozilla-thunderbird | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner | — | — | — | — | — |
| xulrunner-1.9 | — | — | — | — | — |
Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files...
10 affected packages
firefox, firefox-3.0, iceape, icedove, iceweasel...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| firefox-3.0 | — | — | — | — | — |
| iceape | — | — | — | — | — |
| icedove | — | — | — | — | — |
| iceweasel | — | — | — | — | — |
| mozilla-thunderbird | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner | — | — | — | — | — |
| xulrunner-1.9 | — | — | — | — | — |
Some fixes available 24 of 29
Mozilla 1.9 M8 and earlier, Mozilla Firefox 2 before 2.0.0.15, SeaMonkey 1.1.5 and other versions before 1.1.10, Netscape 9.0, and other Mozilla-based web browsers, when a user accepts an SSL server certificate on the basis of the...
9 affected packages
firefox, firefox-3.0, iceape, icedove, iceweasel...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| firefox-3.0 | — | — | — | — | — |
| iceape | — | — | — | — | — |
| icedove | — | — | — | — | — |
| iceweasel | — | — | — | — | — |
| mozilla-thunderbird | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner | — | — | — | — | — |
Some fixes available 24 of 29
The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash)...
9 affected packages
firefox, firefox-3.0, iceape, icedove, iceweasel...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| firefox-3.0 | — | — | — | — | — |
| iceape | — | — | — | — | — |
| icedove | — | — | — | — | — |
| iceweasel | — | — | — | — | — |
| mozilla-thunderbird | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner | — | — | — | — | — |
Some fixes available 14 of 19
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly identify the context of Windows shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site for...
7 affected packages
firefox, firefox-3.0, iceape, icedove, iceweasel...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| firefox-3.0 | — | — | — | — | — |
| iceape | — | — | — | — | — |
| icedove | — | — | — | — | — |
| iceweasel | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| xulrunner | — | — | — | — | — |
Some fixes available 24 of 29
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .properties file for an add-on, which allows remote attackers to read uninitialized memory, as demonstrated by use of ISO 8859 encoding...
9 affected packages
firefox, firefox-3.0, iceape, icedove, iceweasel...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| firefox-3.0 | — | — | — | — | — |
| iceape | — | — | — | — | — |
| icedove | — | — | — | — | — |
| iceweasel | — | — | — | — | — |
| mozilla-thunderbird | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner | — | — | — | — | — |
Some fixes available 24 of 29
The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 does not apply XPCNativeWrappers to scripts loaded from (1) file: URIs, (2) data:...
9 affected packages
firefox, firefox-3.0, iceape, icedove, iceweasel...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| firefox-3.0 | — | — | — | — | — |
| iceape | — | — | — | — | — |
| icedove | — | — | — | — | — |
| iceweasel | — | — | — | — | — |
| mozilla-thunderbird | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner | — | — | — | — | — |
Some fixes available 24 of 29
Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to execute arbitrary code via an XUL document that includes a script from a chrome: URI that points to a...
9 affected packages
firefox, firefox-3.0, iceape, icedove, iceweasel...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| firefox-3.0 | — | — | — | — | — |
| iceape | — | — | — | — | — |
| icedove | — | — | — | — | — |
| iceweasel | — | — | — | — | — |
| mozilla-thunderbird | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner | — | — | — | — | — |
Some fixes available 14 of 19
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors involving (1) an event handler attached to an outer...
7 affected packages
firefox, firefox-3.0, iceape, icedove, iceweasel...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| firefox-3.0 | — | — | — | — | — |
| iceape | — | — | — | — | — |
| icedove | — | — | — | — | — |
| iceweasel | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| xulrunner | — | — | — | — | — |