Search CVE reports


Toggle filters

2721 – 2730 of 2735 results


CVE-2005-2266

Medium priority
Fixed

Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows...

2 affected packages

mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla — — — — —
mozilla-thunderbird — — — — —
Show less packages

CVE-2005-2265

Medium priority
Fixed

Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo...

2 affected packages

mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla — — — — —
mozilla-thunderbird — — — — —
Show less packages

CVE-2005-2261

Medium priority
Fixed

Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.

2 affected packages

mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla — — — — —
mozilla-thunderbird — — — — —
Show less packages

CVE-2005-1532

Medium priority
Fixed

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM...

6 affected packages

firefox, firefox-granparadiso, lightning-sunbird, midbrowser, mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — — — —
firefox-granparadiso — — — — —
lightning-sunbird — — — — —
midbrowser — — — — —
mozilla — — — — —
mozilla-thunderbird — — — — —
Show less packages

CVE-2005-1160

Medium priority
Fixed

The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks...

2 affected packages

mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla — — — — —
mozilla-thunderbird — — — — —
Show less packages

CVE-2005-1159

Medium priority

Some fixes available 3 of 4

The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed, which causes the Javascript interpreter...

2 affected packages

mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla — — — — —
mozilla-thunderbird — — — — —
Show less packages

CVE-2005-0989

Medium priority
Fixed

The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.

2 affected packages

mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla — — — — —
mozilla-thunderbird — — — — —
Show less packages

CVE-2005-0590

Medium priority
Ignored

The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a...

2 affected packages

mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla — — — — —
mozilla-thunderbird — — — — —
Show less packages

CVE-2005-0399

Medium priority

Some fixes available 7 of 8

Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code...

6 affected packages

firefox, firefox-3.0, lightning-sunbird, midbrowser, mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — — — —
firefox-3.0 — — — — —
lightning-sunbird — — — — —
midbrowser — — — — —
mozilla — — — — —
mozilla-thunderbird — — — — —
Show less packages

CVE-2005-0255

Medium priority
Ignored

String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which...

2 affected packages

mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla — — — — —
mozilla-thunderbird — — — — —
Show less packages