Search CVE reports


Toggle filters

531 – 540 of 542 results


CVE-2008-4060

Medium priority

Some fixes available 33 of 39

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome...

8 affected packages

iceape, firefox, firefox-3.0, mozilla-thunderbird, seamonkey...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iceape
firefox
firefox-3.0
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
Show all 8 packages Show less packages

CVE-2008-4059

Medium priority

Some fixes available 33 of 39

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.

8 affected packages

iceape, firefox, firefox-3.0, mozilla-thunderbird, seamonkey...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iceape
firefox
firefox-3.0
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
Show all 8 packages Show less packages

CVE-2008-4058

Medium priority

Some fixes available 33 of 39

The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with...

8 affected packages

firefox, firefox-3.0, iceape, mozilla-thunderbird, seamonkey...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
Show all 8 packages Show less packages

CVE-2008-3837

Low priority

Some fixes available 23 of 29

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop...

6 affected packages

xulrunner-1.9, firefox, firefox-3.0, iceape, seamonkey, xulrunner

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xulrunner-1.9
firefox
firefox-3.0
iceape
seamonkey
xulrunner
Show less packages

CVE-2008-3836

Medium priority

Some fixes available 17 of 23

feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview and the (1) elem.doCommand, (2) elem.dispatchEvent, (3) _setTitleText,...

6 affected packages

firefox, firefox-3.0, iceape, seamonkey, xulrunner, xulrunner-1.9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
seamonkey
xulrunner
xulrunner-1.9
Show less packages

CVE-2008-3835

Medium priority

Some fixes available 33 of 39

The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript...

8 affected packages

thunderbird, firefox, firefox-3.0, iceape, mozilla-thunderbird...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird
firefox
firefox-3.0
iceape
mozilla-thunderbird
seamonkey
xulrunner
xulrunner-1.9
Show all 8 packages Show less packages

CVE-2008-0016

Medium priority

Some fixes available 23 of 29

Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.

6 affected packages

firefox, firefox-3.0, iceape, seamonkey, xulrunner, xulrunner-1.9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
seamonkey
xulrunner
xulrunner-1.9
Show less packages

CVE-2008-3444

Low priority

Some fixes available 6 of 8

The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted but well-formed web page that contains "a simple set...

5 affected packages

firefox, firefox-3.0, iceweasel, xulrunner, xulrunner-1.9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceweasel
xulrunner
xulrunner-1.9
Show less packages

CVE-2008-2934

Low priority
Not affected

Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.

10 affected packages

firefox, firefox-3.0, iceape, icedove, iceweasel...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
icedove
iceweasel
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
Show all 10 packages Show less packages

CVE-2008-2933

Medium priority
Ignored

Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files...

10 affected packages

firefox, firefox-3.0, iceape, icedove, iceweasel...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
icedove
iceweasel
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
Show all 10 packages Show less packages