Search CVE reports


Toggle filters

2661 – 2670 of 3039 results


CVE-2009-3014

Low priority
Ignored

Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly handle javascript: URIs in HTML links within 302 error documents sent from web servers, which...

5 affected packages

firefox, seamonkey, xulrunner-1.9, xulrunner-1.9.1, xulrunner-1.9.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
seamonkey
xulrunner-1.9
xulrunner-1.9.1
xulrunner-1.9.2
Show less packages

CVE-2009-3012

Medium priority
Ignored

Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre does not properly block data: URIs in Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors...

4 affected packages

firefox, seamonkey, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
seamonkey
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-3010

Low priority
Ignored

Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly block data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct...

4 affected packages

firefox, seamonkey, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
seamonkey
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-2953

Negligible priority
Ignored

Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue...

3 affected packages

firefox, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-2665

Medium priority

Some fixes available 1 of 2

The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are enabled, does not properly handle a Link HTTP header, which allows remote attackers...

3 affected packages

firefox, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-2664

Medium priority

Some fixes available 1 of 2

The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial of service (assertion failure and application exit) or possibly execute arbitrary...

3 affected packages

firefox, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-2662

Medium priority

Some fixes available 1 of 2

The browser engine in Mozilla Firefox 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to...

3 affected packages

firefox, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-2470

Low priority

Some fixes available 1 of 2

Mozilla Firefox before 3.0.12, and 3.5.x before 3.5.2, allows remote SOCKS5 proxy servers to cause a denial of service (data stream corruption) via a long domain name in a reply.

3 affected packages

firefox, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-2663

Medium priority

Some fixes available 4 of 6

libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary...

4 affected packages

firefox, libvorbis, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
libvorbis
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-2654

Medium priority
Fixed

Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL,...

4 affected packages

firefox-3.0, firefox-3.5, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-3.0
firefox-3.5
xulrunner-1.9
xulrunner-1.9.1
Show less packages