Search CVE reports


Toggle filters

2381 – 2389 of 2389 results


CVE-2005-0989

Medium priority
Fixed

The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.

2 affected packages

mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla
mozilla-thunderbird
Show less packages

CVE-2005-0590

Medium priority
Ignored

The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a...

2 affected packages

mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla
mozilla-thunderbird
Show less packages

CVE-2005-0399

Medium priority

Some fixes available 7 of 8

Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code...

6 affected packages

firefox, firefox-3.0, lightning-sunbird, midbrowser, mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
firefox-3.0
lightning-sunbird
midbrowser
mozilla
mozilla-thunderbird
Show less packages

CVE-2005-0255

Medium priority
Ignored

String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which...

2 affected packages

mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla
mozilla-thunderbird
Show less packages

CVE-2005-0230

Medium priority
Not affected

Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended...

2 affected packages

mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla
mozilla-thunderbird
Show less packages

CVE-2005-0142

Medium priority
Ignored

Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to...

2 affected packages

mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla
mozilla-thunderbird
Show less packages

CVE-2005-0592

Medium priority
Fixed

Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a...

2 affected packages

mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla
mozilla-thunderbird
Show less packages

CVE-2005-0587

Medium priority
Fixed

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the...

2 affected packages

mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla
mozilla-thunderbird
Show less packages

CVE-2005-0149

Medium priority
Ignored

Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using...

2 affected packages

mozilla, mozilla-thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozilla
mozilla-thunderbird
Show less packages