Search CVE reports
481 – 490 of 542 results
Some fixes available 4 of 6
Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of...
7 affected packages
firefox, firefox-3.0, iceape, iceweasel, seamonkey...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | — | — | — | — |
firefox-3.0 | — | — | — | — |
iceape | — | — | — | — |
iceweasel | — | — | — | — |
seamonkey | — | — | — | — |
xulrunner | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and...
7 affected packages
firefox, iceape, firefox-3.0, iceweasel, seamonkey...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | — | — | — | — |
iceape | — | — | — | — |
firefox-3.0 | — | — | — | — |
iceweasel | — | — | — | — |
seamonkey | — | — | — | — |
xulrunner | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
Some fixes available 4 of 6
Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS)...
7 affected packages
firefox, firefox-3.0, iceape, iceweasel, seamonkey...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | — | — | — | — |
firefox-3.0 | — | — | — | — |
iceape | — | — | — | — |
iceweasel | — | — | — | — |
seamonkey | — | — | — | — |
xulrunner | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
Some fixes available 15 of 20
Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information...
5 affected packages
firefox, iceape, seamonkey, xulrunner, xulrunner-1.9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | — | — | — | — |
iceape | — | — | — | — |
seamonkey | — | — | — | — |
xulrunner | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
Some fixes available 7 of 12
components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a...
5 affected packages
firefox, iceape, seamonkey, xulrunner, xulrunner-1.9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | — | — | — | — |
iceape | — | — | — | — |
seamonkey | — | — | — | — |
xulrunner | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
Some fixes available 7 of 13
Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly...
10 affected packages
iceape, firefox, firefox-3.0, icedove, iceweasel...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
iceape | — | — | — | — |
firefox | — | — | — | — |
firefox-3.0 | — | — | — | — |
icedove | — | — | — | — |
iceweasel | — | — | — | — |
mozilla-thunderbird | — | — | — | — |
seamonkey | — | — | — | — |
thunderbird | — | — | — | — |
xulrunner | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
Some fixes available 14 of 18
Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or...
10 affected packages
firefox, firefox-3.0, iceape, icedove, iceweasel...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | — | — | — | — |
firefox-3.0 | — | — | — | — |
iceape | — | — | — | — |
icedove | — | — | — | — |
iceweasel | — | — | — | — |
mozilla-thunderbird | — | — | — | — |
seamonkey | — | — | — | — |
thunderbird | — | — | — | — |
xulrunner | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Status Bar Obfuscation" and "Clickjacking" attack.
10 affected packages
firefox, firefox-3.0, iceape, icedove, iceweasel...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | — | — | — | — |
firefox-3.0 | — | — | — | — |
iceape | — | — | — | — |
icedove | — | — | — | — |
iceweasel | — | — | — | — |
mozilla-thunderbird | — | — | — | — |
seamonkey | — | — | — | — |
thunderbird | — | — | — | — |
xulrunner | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
Some fixes available 5 of 12
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session,...
4 affected packages
xulrunner-1.9.2, firefox, xulrunner-1.9, xulrunner-1.9.1
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
xulrunner-1.9.2 | — | — | — | — |
firefox | — | — | — | — |
xulrunner-1.9 | — | — | — | — |
xulrunner-1.9.1 | — | — | — | — |
Some fixes available 3 of 6
Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild...
2 affected packages
firefox, xulrunner-1.9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | — | — | — | — |
xulrunner-1.9 | — | — | — | — |