Search CVE reports
1951 – 1960 of 2389 results
Off-by-one error in the png_formatted_warning function in pngerror.c in libpng 1.5.4 through 1.5.7 might allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified...
4 affected packages
chromium-browser, firefox, libpng, thunderbird
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| chromium-browser | — | — | — | — | — |
| firefox | — | — | — | — | — |
| libpng | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
Some fixes available 8 of 18
Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly implement the JavaScript sandbox utility, which allows...
5 affected packages
firefox, seamonkey, thunderbird, xulrunner-1.9.2, xulrunner-2.0
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner-1.9.2 | — | — | — | — | — |
| xulrunner-2.0 | — | — | — | — | — |
Some fixes available 4 of 14
Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not have the same context-menu restrictions for data: URLs as for javascript: URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks...
5 affected packages
firefox, seamonkey, thunderbird, xulrunner-1.9.2, xulrunner-2.0
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner-1.9.2 | — | — | — | — | — |
| xulrunner-2.0 | — | — | — | — | — |
Some fixes available 4 of 14
Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not properly establish the security context of a feed: URL, which allows remote attackers to bypass unspecified cross-site scripting (XSS)...
5 affected packages
firefox, seamonkey, thunderbird, xulrunner-1.9.2, xulrunner-2.0
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner-1.9.2 | — | — | — | — | — |
| xulrunner-2.0 | — | — | — | — | — |
Some fixes available 8 of 18
The certificate-warning functionality in browser/components/certerror/content/aboutCertError.xhtml in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before...
5 affected packages
firefox, seamonkey, thunderbird, xulrunner-1.9.2, xulrunner-2.0
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner-1.9.2 | — | — | — | — | — |
| xulrunner-2.0 | — | — | — | — | — |
Some fixes available 8 of 18
The Content Security Policy (CSP) functionality in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly...
5 affected packages
firefox, seamonkey, thunderbird, xulrunner-1.9.2, xulrunner-2.0
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner-1.9.2 | — | — | — | — | — |
| xulrunner-2.0 | — | — | — | — | — |
Some fixes available 8 of 18
Use-after-free vulnerability in the JSDependentString::undepend function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before...
5 affected packages
firefox, seamonkey, thunderbird, xulrunner-1.9.2, xulrunner-2.0
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner-1.9.2 | — | — | — | — | — |
| xulrunner-2.0 | — | — | — | — | — |
Some fixes available 8 of 18
Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly handle duplicate values in X-Frame-Options headers,...
5 affected packages
firefox, seamonkey, thunderbird, xulrunner-1.9.2, xulrunner-2.0
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner-1.9.2 | — | — | — | — | — |
| xulrunner-2.0 | — | — | — | — | — |
Some fixes available 8 of 18
The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through 13.0, and SeaMonkey before 2.11 might allow remote attackers to obtain sensitive information...
5 affected packages
firefox, seamonkey, thunderbird, xulrunner-1.9.2, xulrunner-2.0
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner-1.9.2 | — | — | — | — | — |
| xulrunner-2.0 | — | — | — | — | — |
Some fixes available 8 of 18
Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not consider the presence of same-compartment security wrappers...
5 affected packages
firefox, seamonkey, thunderbird, xulrunner-1.9.2, xulrunner-2.0
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | — | — |
| seamonkey | — | — | — | — | — |
| thunderbird | — | — | — | — | — |
| xulrunner-1.9.2 | — | — | — | — | — |
| xulrunner-2.0 | — | — | — | — | — |