Vulnerabilities (CVE)

Vendor filter

Mozilla Subscribe

Product filter

Seamonkey Subscribe

Filter

698 total CVE
CVE Vendors Products Updated CVSS
CVE-2015-4000 12 Google, Openssl, Apple and 9 more 25 Safari, Network Security Services, Ie and 22 more 2019-10-09 4.3
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a...
CVE-2007-4841 1 Mozilla 3 Firefox, Thunderbird, Seamonkey 2019-10-09 9.3
Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execute arbitrary commands via a (1) mailto, (2) nntp, (3) news, or (4) snews URI with invalid "%" encoding, related to improper...
CVE-2007-0994 2 Mozilla, Debian 3 Firefox, Seamonkey, Debian Linux 2019-10-09 6.8
A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript:...
CVE-2007-0780 2 Mozilla, Canonical 3 Firefox, Seamonkey, Ubuntu Linux 2019-10-09 6.8
browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a...
CVE-2007-0778 3 Mozilla, Canonical, Debian 4 Firefox, Seamonkey, Ubuntu Linux and 1 more 2019-10-09 5.4
The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain...
CVE-2007-0777 2 Mozilla, Canonical 4 Firefox, Seamonkey, Thunderbird and 1 more 2019-10-09 9.3
The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain...
CVE-2007-0009 3 Mozilla, Canonical, Debian 6 Firefox, Seamonkey, Thunderbird and 3 more 2019-10-09 6.8
Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System...
CVE-2006-6500 3 Mozilla, Canonical, Debian 5 Firefox, Seamonkey, Thunderbird and 2 more 2019-10-09 6.8
Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by...
CVE-2006-6499 3 Mozilla, Canonical, Debian 5 Firefox, Seamonkey, Thunderbird and 2 more 2019-10-09 4.3
The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote...
CVE-2011-3866 1 Mozilla 2 Firefox, Seamonkey 2018-11-29 4.3
Mozilla Firefox before 7.0 and SeaMonkey before 2.4 do not properly restrict availability of motion data events, which makes it easier for remote attackers to read keystrokes by leveraging JavaScript code running in a background tab.
CVE-2011-3003 1 Mozilla 2 Firefox, Seamonkey 2018-11-29 10.0
Mozilla Firefox before 7.0 and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unspecified WebGL test case that triggers a memory-allocation error and a...
CVE-2011-3002 1 Mozilla 2 Firefox, Seamonkey 2018-11-29 9.3
Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox before 7.0 and SeaMonkey before 2.4, does not validate the return value of a GrowAtomTable function call, which allows remote attackers to cause a denial of service...
CVE-2010-0159 3 Mozilla, Canonical, Debian 5 Firefox, Seamonkey, Thunderbird and 2 more 2018-11-16 10.0
The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly...
CVE-2008-5513 3 Mozilla, Canonical, Debian 5 Firefox, Seamonkey, Thunderbird and 2 more 2018-11-08 4.3
Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote attackers to bypass the same origin policy, inject content into documents associated with other domains, and...
CVE-2008-5511 3 Mozilla, Canonical, Debian 5 Firefox, Seamonkey, Thunderbird and 2 more 2018-11-08 4.3
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and conduct cross-site scripting (XSS) attacks via an XBL binding...
CVE-2008-5510 3 Mozilla, Canonical, Debian 5 Firefox, Seamonkey, Thunderbird and 2 more 2018-11-08 5.0
The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection...
CVE-2008-5508 3 Mozilla, Canonical, Debian 5 Firefox, Seamonkey, Thunderbird and 2 more 2018-11-08 4.3
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse URLs with leading whitespace or control characters, which might allow remote attackers to...
CVE-2008-5507 3 Mozilla, Canonical, Debian 5 Firefox, Seamonkey, Thunderbird and 2 more 2018-11-08 6.0
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript...
CVE-2008-5506 3 Mozilla, Canonical, Debian 5 Firefox, Seamonkey, Thunderbird and 2 more 2018-11-08 6.8
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy by causing the browser to issue an XMLHttpRequest to an...
CVE-2008-5502 2 Mozilla, Canonical 4 Firefox, Seamonkey, Thunderbird and 1 more 2018-11-08 5.0
The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the...