Search CVE reports


Toggle filters

2771 – 2780 of 3080 results


CVE-2009-0357

Medium priority

Some fixes available 15 of 20

Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information...

5 affected packages

firefox, iceape, seamonkey, xulrunner, xulrunner-1.9

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
iceape
seamonkey
xulrunner
xulrunner-1.9
Show less packages

CVE-2009-0355

Medium priority

Some fixes available 7 of 12

components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a...

5 affected packages

firefox, iceape, seamonkey, xulrunner, xulrunner-1.9

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
iceape
seamonkey
xulrunner
xulrunner-1.9
Show less packages

CVE-2009-0353

Medium priority

Some fixes available 7 of 13

Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly...

10 affected packages

iceape, firefox, firefox-3.0, icedove, iceweasel...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iceape
firefox
firefox-3.0
icedove
iceweasel
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
Show all 10 packages Show less packages

CVE-2009-0352

Medium priority

Some fixes available 14 of 18

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or...

10 affected packages

firefox, firefox-3.0, iceape, icedove, iceweasel...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
icedove
iceweasel
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
Show all 10 packages Show less packages

CVE-2009-0253

Low priority
Ignored

Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Status Bar Obfuscation" and "Clickjacking" attack.

10 affected packages

firefox, firefox-3.0, iceape, icedove, iceweasel...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
icedove
iceweasel
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
Show all 10 packages Show less packages

CVE-2008-5913

Low priority

Some fixes available 5 of 12

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session,...

4 affected packages

xulrunner-1.9.2, firefox, xulrunner-1.9, xulrunner-1.9.1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xulrunner-1.9.2
firefox
xulrunner-1.9
xulrunner-1.9.1
Show less packages

CVE-2009-0071

Low priority

Some fixes available 3 of 6

Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild...

2 affected packages

firefox, xulrunner-1.9

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
xulrunner-1.9
Show less packages

CVE-2004-2761

Low priority
Fixed

The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509...

2 affected packages

firefox, nss

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
nss
Show less packages

CVE-2008-5715

Negligible priority
Ignored

Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long string value for the hash property (aka location.hash). NOTE: it was later reported...

7 affected packages

firefox, firefox-3.0, iceape, iceweasel, seamonkey...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
iceweasel
seamonkey
xulrunner
xulrunner-1.9
Show all 7 packages Show less packages

CVE-2008-5505

Medium priority

Some fixes available 4 of 6

Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entities that are similar to cookies.

2 affected packages

firefox-3.0, xulrunner-1.9

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-3.0
xulrunner-1.9
Show less packages