Search CVE reports
31 – 40 of 164 results
Some fixes available 17 of 26
Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to execute arbitrary code via vectors involving multiple plugin instances.
6 affected packages
seamonkey, firefox, xulrunner, xulrunner-1.9, xulrunner-1.9.1, xulrunner-1.9.2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
seamonkey | — | — | — | — |
firefox | — | — | — | — |
xulrunner | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
xulrunner-1.9.1 | — | — | — | — |
xulrunner-1.9.2 | — | — | — | — |
Some fixes available 17 of 26
Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not properly handle situations in which both "Content-Disposition: attachment" and "Content-Type: multipart" are present in HTTP headers,...
6 affected packages
firefox, seamonkey, xulrunner, xulrunner-1.9, xulrunner-1.9.1, xulrunner-1.9.2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | — | — | — | — |
seamonkey | — | — | — | — |
xulrunner | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
xulrunner-1.9.1 | — | — | — | — |
xulrunner-1.9.2 | — | — | — | — |
Some fixes available 21 of 33
Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to...
7 affected packages
firefox, seamonkey, thunderbird, xulrunner, xulrunner-1.9...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | — | — | — | — |
seamonkey | — | — | — | — |
thunderbird | — | — | — | — |
xulrunner | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
xulrunner-1.9.1 | — | — | — | — |
xulrunner-1.9.2 | — | — | — | — |
Some fixes available 5 of 11
The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended...
4 affected packages
firefox, xulrunner-1.9, xulrunner-1.9.1, xulrunner-1.9.2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
xulrunner-1.9.1 | — | — | — | — |
xulrunner-1.9.2 | — | — | — | — |
Some fixes available 6 of 12
Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote attackers to conduct use-after-free attacks and execute arbitrary code...
5 affected packages
firefox, thunderbird, xulrunner-1.9, xulrunner-1.9.1, xulrunner-1.9.2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | — | — | — | — |
thunderbird | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
xulrunner-1.9.1 | — | — | — | — |
xulrunner-1.9.2 | — | — | — | — |
Some fixes available 18 of 34
Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an...
7 affected packages
firefox, seamonkey, thunderbird, xulrunner, xulrunner-1.9...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | — | — | — | — |
seamonkey | — | — | — | — |
thunderbird | — | — | — | — |
xulrunner | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
xulrunner-1.9.1 | — | — | — | — |
xulrunner-1.9.2 | — | — | — | — |
Some fixes available 3 of 6
The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory...
4 affected packages
firefox, xulrunner-1.9, xulrunner-1.9.1, xulrunner-1.9.2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
xulrunner-1.9.1 | — | — | — | — |
xulrunner-1.9.2 | — | — | — | — |
Some fixes available 4 of 6
Use-after-free vulnerability in the nsCycleCollector::MarkRoots function in Mozilla Firefox 3.5.x before 3.5.10 and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a crafted HTML document, related to...
2 affected packages
seamonkey, xulrunner-1.9.1
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
seamonkey | — | — | — | — |
xulrunner-1.9.1 | — | — | — | — |
Some fixes available 14 of 28
The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML...
6 affected packages
firefox, seamonkey, thunderbird, xulrunner, xulrunner-1.9, xulrunner-1.9.1
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | — | — | — | — |
seamonkey | — | — | — | — |
thunderbird | — | — | — | — |
xulrunner | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
xulrunner-1.9.1 | — | — | — | — |
Some fixes available 10 of 20
Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remote attackers...
7 affected packages
seamonkey, firefox, firefox-3.0, firefox-3.5, xulrunner...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
seamonkey | — | — | — | — |
firefox | — | — | — | — |
firefox-3.0 | — | — | — | — |
firefox-3.5 | — | — | — | — |
xulrunner | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
xulrunner-1.9.1 | — | — | — | — |