Search CVE reports


Toggle filters

111 – 120 of 227 results


CVE-2010-1208

Medium priority

Some fixes available 8 of 11

Use-after-free vulnerability in the attribute-cloning functionality in the DOM implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary...

4 affected packages

firefox, firefox-3.0, firefox-3.5, xulrunner-1.9.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
firefox-3.5
xulrunner-1.9.2
Show less packages

CVE-2010-1207

Medium priority

Some fixes available 8 of 11

Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference...

4 affected packages

firefox, firefox-3.0, firefox-3.5, xulrunner-1.9.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
firefox-3.5
xulrunner-1.9.2
Show less packages

CVE-2010-1206

Medium priority

Some fixes available 12 of 15

The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in...

5 affected packages

firefox, firefox-3.0, firefox-3.5, seamonkey, xulrunner-1.9.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
firefox-3.5
seamonkey
xulrunner-1.9.2
Show less packages

CVE-2010-0181

Negligible priority

Some fixes available 10 of 20

Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remote attackers...

7 affected packages

seamonkey, firefox, firefox-3.0, firefox-3.5, xulrunner...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
seamonkey
firefox
firefox-3.0
firefox-3.5
xulrunner
xulrunner-1.9
xulrunner-1.9.1
Show all 7 packages Show less packages

CVE-2009-5017

Medium priority
Ignored

Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a...

6 affected packages

firefox, firefox-3.0, firefox-3.5, seamonkey, thunderbird, xulrunner-1.9.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
firefox-3.5
seamonkey
thunderbird
xulrunner-1.9.2
Show less packages

CVE-2009-3987

Low priority
Not affected

The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry,...

5 affected packages

firefox-3.0, firefox-3.5, seamonkey, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-3.0
firefox-3.5
seamonkey
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-3981

Medium priority
Fixed

Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly...

2 affected packages

firefox-3.0, xulrunner-1.9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-3.0
xulrunner-1.9
Show less packages

CVE-2009-3382

Medium priority
Fixed

layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and...

2 affected packages

firefox-3.0, xulrunner-1.9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-3.0
xulrunner-1.9
Show less packages

CVE-2009-3380

Medium priority
Fixed

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly...

4 affected packages

firefox-3.0, firefox-3.5, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-3.0
firefox-3.5
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-3376

Low priority
Fixed

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof...

5 affected packages

firefox-3.0, firefox-3.5, thunderbird, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-3.0
firefox-3.5
thunderbird
xulrunner-1.9
xulrunner-1.9.1
Show less packages