Search CVE reports


Toggle filters

2721 – 2730 of 3039 results


CVE-2009-0776

Low priority

Some fixes available 26 of 31

nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.

9 affected packages

firefox, iceape, icedove, mozilla-thunderbird, seamonkey...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
iceape
icedove
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
xulrunner-1.9.1
Show all 9 packages Show less packages

CVE-2009-0775

Medium priority

Some fixes available 10 of 14

Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and...

12 affected packages

firefox, firefox-3.0, firefox-3.5, iceape, icedove...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
firefox-3.5
iceape
icedove
iceweasel
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
xulrunner-1.9.1
Show all 12 packages Show less packages

CVE-2009-0774

Low priority

Some fixes available 26 of 31

The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to...

9 affected packages

firefox, iceape, icedove, mozilla-thunderbird, seamonkey...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
iceape
icedove
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
xulrunner-1.9.1
Show all 9 packages Show less packages

CVE-2009-0772

Low priority

Some fixes available 26 of 31

The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to...

9 affected packages

firefox, iceape, icedove, mozilla-thunderbird, seamonkey...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
iceape
icedove
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
xulrunner-1.9.1
Show all 9 packages Show less packages

CVE-2009-0040

Medium priority

Some fixes available 15 of 31

The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute...

12 affected packages

icedove, firefox, firefox-3.0, firefox-3.5, iceape...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icedove
firefox
firefox-3.0
firefox-3.5
iceape
libpng
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
xulrunner-1.9.1
Show all 12 packages Show less packages

CVE-2009-0652

Medium priority

Some fixes available 13 of 23

The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows...

6 affected packages

firefox, iceape, seamonkey, xulrunner, xulrunner-1.9, xulrunner-1.9.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
iceape
seamonkey
xulrunner
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-0358

Low priority

Some fixes available 4 of 6

Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of...

7 affected packages

firefox, firefox-3.0, iceape, iceweasel, seamonkey...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
iceweasel
seamonkey
xulrunner
xulrunner-1.9
Show all 7 packages Show less packages

CVE-2009-0356

Medium priority
Not affected

Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and...

7 affected packages

firefox, iceape, firefox-3.0, iceweasel, seamonkey...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
iceape
firefox-3.0
iceweasel
seamonkey
xulrunner
xulrunner-1.9
Show all 7 packages Show less packages

CVE-2009-0354

Low priority

Some fixes available 4 of 6

Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS)...

7 affected packages

firefox, firefox-3.0, iceape, iceweasel, seamonkey...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
iceweasel
seamonkey
xulrunner
xulrunner-1.9
Show all 7 packages Show less packages

CVE-2009-0357

Medium priority

Some fixes available 15 of 20

Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information...

5 affected packages

firefox, iceape, seamonkey, xulrunner, xulrunner-1.9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
iceape
seamonkey
xulrunner
xulrunner-1.9
Show less packages