Search CVE reports


Toggle filters

121 – 130 of 164 results


CVE-2009-2044

Low priority

Some fixes available 1 of 5

Mozilla Firefox 3.0.10 and earlier on Linux allows remote attackers to cause a denial of service (application crash) via a URI for a large GIF image in the BACKGROUND attribute of a BODY element.

3 affected packages

firefox, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-2043

Low priority

Some fixes available 9 of 11

nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to interaction with TinyMCE.

4 affected packages

firefox, seamonkey, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
seamonkey
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-2042

Low priority

Some fixes available 8 of 21

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers...

7 affected packages

libpng, mozilla-thunderbird, seamonkey, thunderbird, xulrunner...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libpng
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
xulrunner-1.9.1
Show all 7 packages Show less packages

CVE-2009-1841

Medium priority

Some fixes available 21 of 28

js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object,...

7 affected packages

mozilla-thunderbird, firefox, seamonkey, thunderbird, xulrunner...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla-thunderbird
firefox
seamonkey
thunderbird
xulrunner
xulrunner-1.9
xulrunner-1.9.1
Show all 7 packages Show less packages

CVE-2009-1840

Low priority

Some fixes available 5 of 19

Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML...

5 affected packages

firefox, thunderbird, xulrunner, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
thunderbird
xulrunner
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-1839

Low priority

Some fixes available 5 of 6

Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted...

3 affected packages

firefox, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-1838

Medium priority

Some fixes available 21 of 28

The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner document to null in unspecified circumstances, which allows remote attackers...

7 affected packages

firefox, mozilla-thunderbird, seamonkey, thunderbird, xulrunner...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
xulrunner-1.9.1
Show all 7 packages Show less packages

CVE-2009-1837

Medium priority

Some fixes available 5 of 6

Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transition during...

3 affected packages

firefox, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-1836

Medium priority

Some fixes available 21 of 28

Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows...

7 affected packages

firefox, mozilla-thunderbird, seamonkey, thunderbird, xulrunner...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
xulrunner-1.9.1
Show all 7 packages Show less packages

CVE-2009-1835

Medium priority

Some fixes available 9 of 11

Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assisted remote attackers to read arbitrary cookies via...

4 affected packages

firefox, seamonkey, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
seamonkey
xulrunner-1.9
xulrunner-1.9.1
Show less packages