Search CVE reports


Toggle filters

2631 – 2640 of 3039 results


CVE-2009-3388

Medium priority

Some fixes available 6 of 8

liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to...

3 affected packages

firefox, seamonkey, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
seamonkey
xulrunner-1.9.1
Show less packages

CVE-2009-4102

Medium priority
Ignored

Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.

1 affected package

firefox-sage

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-sage
Show less packages

CVE-2009-3383

Medium priority
Fixed

Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code...

2 affected packages

firefox-3.5, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-3.5
xulrunner-1.9.1
Show less packages

CVE-2009-3382

Medium priority
Fixed

layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and...

2 affected packages

firefox-3.0, xulrunner-1.9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-3.0
xulrunner-1.9
Show less packages

CVE-2009-3381

Medium priority
Fixed

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via...

2 affected packages

firefox-3.5, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-3.5
xulrunner-1.9.1
Show less packages

CVE-2009-3380

Medium priority
Fixed

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly...

4 affected packages

firefox-3.0, firefox-3.5, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-3.0
firefox-3.5
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-3378

Medium priority

Some fixes available 3 of 6

The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon encountering a...

3 affected packages

firefox, xulrunner-1.9.1, xulrunner-1.9.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
xulrunner-1.9.1
xulrunner-1.9.2
Show less packages

CVE-2009-3375

Low priority
Fixed

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the...

4 affected packages

firefox-3.0, firefox-3.5, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-3.0
firefox-3.5
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-3374

Medium priority
Fixed

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects...

4 affected packages

firefox-3.0, firefox-3.5, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-3.0
firefox-3.5
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-3371

Medium priority
Fixed

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.

2 affected packages

firefox-3.5, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-3.5
xulrunner-1.9.1
Show less packages