Search CVE reports


Toggle filters

141 – 150 of 227 results


CVE-2009-0356

Medium priority
Not affected

Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and...

7 affected packages

firefox, iceape, firefox-3.0, iceweasel, seamonkey...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
iceape
firefox-3.0
iceweasel
seamonkey
xulrunner
xulrunner-1.9
Show all 7 packages Show less packages

CVE-2009-0354

Low priority

Some fixes available 4 of 6

Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS)...

7 affected packages

firefox, firefox-3.0, iceape, iceweasel, seamonkey...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
iceweasel
seamonkey
xulrunner
xulrunner-1.9
Show all 7 packages Show less packages

CVE-2009-0353

Medium priority

Some fixes available 7 of 13

Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly...

10 affected packages

iceape, firefox, firefox-3.0, icedove, iceweasel...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iceape
firefox
firefox-3.0
icedove
iceweasel
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
Show all 10 packages Show less packages

CVE-2009-0352

Medium priority

Some fixes available 14 of 18

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or...

10 affected packages

firefox, firefox-3.0, iceape, icedove, iceweasel...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
icedove
iceweasel
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
Show all 10 packages Show less packages

CVE-2009-0253

Low priority
Ignored

Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Status Bar Obfuscation" and "Clickjacking" attack.

10 affected packages

firefox, firefox-3.0, iceape, icedove, iceweasel...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
icedove
iceweasel
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
Show all 10 packages Show less packages

CVE-2009-0040

Medium priority

Some fixes available 15 of 31

The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute...

12 affected packages

icedove, firefox, firefox-3.0, firefox-3.5, iceape...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icedove
firefox
firefox-3.0
firefox-3.5
iceape
libpng
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
xulrunner-1.9.1
Show all 12 packages Show less packages

CVE-2008-7293

Medium priority

Some fixes available 3 of 6

Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an...

7 affected packages

firefox, firefox-3.0, firefox-3.5, seamonkey, thunderbird...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
firefox-3.5
seamonkey
thunderbird
xulrunner-1.9.2
xulrunner-2.0
Show all 7 packages Show less packages

CVE-2008-7244

Low priority
Ignored

Mozilla Firefox 3.0.1 and earlier allows remote attackers to cause a denial of service (browser hang) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

9 affected packages

firefox, firefox-3.0, firefox-3.5, mozilla-thunderbird, seamonkey...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
firefox-3.5
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
xulrunner-1.9.1
Show all 9 packages Show less packages

CVE-2008-5715

Negligible priority
Ignored

Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long string value for the hash property (aka location.hash). NOTE: it was later reported...

7 affected packages

firefox, firefox-3.0, iceape, iceweasel, seamonkey...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
iceweasel
seamonkey
xulrunner
xulrunner-1.9
Show all 7 packages Show less packages

CVE-2008-5513

Medium priority

Some fixes available 15 of 19

Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote attackers to bypass the same origin policy, inject content into documents associated with...

4 affected packages

firefox, firefox-3.0, xulrunner, xulrunner-1.9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
xulrunner
xulrunner-1.9
Show less packages