Search CVE reports


Toggle filters

2231 – 2240 of 2389 results


CVE-2008-4058

Medium priority

Some fixes available 33 of 39

The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with...

8 affected packages

firefox, firefox-3.0, iceape, mozilla-thunderbird, seamonkey...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
Show all 8 packages Show less packages

CVE-2008-3835

Medium priority

Some fixes available 33 of 39

The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript...

8 affected packages

thunderbird, firefox, firefox-3.0, iceape, mozilla-thunderbird...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird
firefox
firefox-3.0
iceape
mozilla-thunderbird
seamonkey
xulrunner
xulrunner-1.9
Show all 8 packages Show less packages

CVE-2008-2934

Low priority
Not affected

Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.

10 affected packages

firefox, firefox-3.0, iceape, icedove, iceweasel...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
icedove
iceweasel
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
Show all 10 packages Show less packages

CVE-2008-2933

Medium priority
Ignored

Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files...

10 affected packages

firefox, firefox-3.0, iceape, icedove, iceweasel...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
icedove
iceweasel
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
xulrunner-1.9
Show all 10 packages Show less packages

CVE-2008-2809

Low priority

Some fixes available 24 of 29

Mozilla 1.9 M8 and earlier, Mozilla Firefox 2 before 2.0.0.15, SeaMonkey 1.1.5 and other versions before 1.1.10, Netscape 9.0, and other Mozilla-based web browsers, when a user accepts an SSL server certificate on the basis of the...

9 affected packages

iceape, firefox, firefox-3.0, icedove, iceweasel...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iceape
firefox
firefox-3.0
icedove
iceweasel
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
Show all 9 packages Show less packages

CVE-2008-2811

Medium priority

Some fixes available 24 of 29

The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash)...

9 affected packages

firefox, firefox-3.0, iceape, icedove, iceweasel...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
icedove
iceweasel
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
Show all 9 packages Show less packages

CVE-2008-2807

Low priority

Some fixes available 24 of 29

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .properties file for an add-on, which allows remote attackers to read uninitialized memory, as demonstrated by use of ISO 8859 encoding...

9 affected packages

firefox, firefox-3.0, iceape, icedove, iceweasel...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
icedove
iceweasel
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
Show all 9 packages Show less packages

CVE-2008-2803

Medium priority

Some fixes available 24 of 29

The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 does not apply XPCNativeWrappers to scripts loaded from (1) file: URIs, (2) data:...

9 affected packages

thunderbird, firefox, firefox-3.0, iceape, icedove...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
thunderbird
firefox
firefox-3.0
iceape
icedove
iceweasel
mozilla-thunderbird
seamonkey
xulrunner
Show all 9 packages Show less packages

CVE-2008-2802

Medium priority

Some fixes available 24 of 29

Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to execute arbitrary code via an XUL document that includes a script from a chrome: URI that points to a...

9 affected packages

icedove, firefox, firefox-3.0, iceape, iceweasel...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icedove
firefox
firefox-3.0
iceape
iceweasel
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
Show all 9 packages Show less packages

CVE-2008-2799

Medium priority

Some fixes available 24 of 29

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to cause a denial of service (application crash) and possibly execute...

9 affected packages

firefox, firefox-3.0, iceape, icedove, iceweasel...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
iceape
icedove
iceweasel
mozilla-thunderbird
seamonkey
thunderbird
xulrunner
Show all 9 packages Show less packages