Search CVE reports


Toggle filters

2611 – 2620 of 2735 results


CVE-2007-3844

Medium priority
Fixed

Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2)...

4 affected packages

firefox, iceape, midbrowser, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — — — —
iceape — — — — —
midbrowser — — — — —
mozilla-thunderbird — — — — —
Show less packages

CVE-2007-4039

Medium priority
Not affected

Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified...

1 affected package

mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla-thunderbird — — — — —
Show less packages

CVE-2007-3735

Medium priority
Fixed

Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to cause a denial of service (crash) via unspecified vectors that trigger memory...

4 affected packages

firefox, iceape, midbrowser, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — — — —
iceape — — — — —
midbrowser — — — — —
mozilla-thunderbird — — — — —
Show less packages

CVE-2007-3734

Medium priority
Fixed

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to cause a denial of service (crash) via unspecified vectors that trigger memory corruption.

4 affected packages

firefox, iceape, midbrowser, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — — — —
iceape — — — — —
midbrowser — — — — —
mozilla-thunderbird — — — — —
Show less packages

CVE-2007-3670

Medium priority
Fixed

Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary...

3 affected packages

firefox, midbrowser, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — — — —
midbrowser — — — — —
mozilla-thunderbird — — — — —
Show less packages

CVE-2007-3511

Low priority
Fixed

The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for"...

3 affected packages

firefox, mozilla-thunderbird, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — — — —
mozilla-thunderbird — — — — —
thunderbird — — — — —
Show less packages

CVE-2007-2868

Medium priority
Fixed

Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to...

5 affected packages

firefox, iceape, lightning-sunbird, midbrowser, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — — — —
iceape — — — — —
lightning-sunbird — — — — —
midbrowser — — — — —
mozilla-thunderbird — — — — —
Show less packages

CVE-2007-2867

Medium priority
Fixed

Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to...

5 affected packages

firefox, iceape, lightning-sunbird, midbrowser, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — — — —
iceape — — — — —
lightning-sunbird — — — — —
midbrowser — — — — —
mozilla-thunderbird — — — — —
Show less packages

CVE-2007-2292

Low priority
Fixed

CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF (%0a) bytes in the username attribute.

3 affected packages

firefox, mozilla-thunderbird, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — — — —
mozilla-thunderbird — — — — —
thunderbird — — — — —
Show less packages

CVE-2007-1558

Medium priority

Some fixes available 6 of 21

The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions. NOTE: this design-level issue potentially affects all...

8 affected packages

fetchmail, iceape, im, mew, mew-beta...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fetchmail — — — — —
iceape — — — — —
im — — — — —
mew — — — — —
mew-beta — — — — —
mozilla-thunderbird — — — — —
wl — — — — —
wl-beta — — — — —
Show all 8 packages Show less packages