Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
704 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 5.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+11 | 29/8/2012 | 16/6/2026 | Use-after-free vulnerability in the gfxTextRun::CanBreakLineBefore function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory… | |
| Modificada | Alta (10) | 5.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+11 | 29/8/2012 | 16/6/2026 | Use-after-free vulnerability in the nsObjectLoadingContent::LoadObject function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap… | |
| Modificada | Alta (10) | 5.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+11 | 29/8/2012 | 16/6/2026 | Use-after-free vulnerability in the nsHTMLEditor::CollapseAdjacentTextNodes function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service… | |
| Modificada | Alta (9.3) | 3.8% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Seamonkey | 29/8/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to garbage collection after… | |
| Modificada | Alta (10) | 5.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+11 | 29/8/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly… | |
| Modificada | Media (4.3) | 1.9% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Seamonkey | 29/8/2012 | 16/6/2026 | Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin. | |
| Modificada | Alta (10) | 4.0% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRMozilla Seamonkey | 18/7/2012 | 16/6/2026 | Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly implement the JavaScript sandbox utility, which allows remote attackers to execute arbitrary JavaScript code with improper privileges via a… | |
| Modificada | Media (4) | 0.90% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRMozilla Seamonkey | 18/7/2012 | 16/6/2026 | The certificate-warning functionality in browser/components/certerror/content/aboutCertError.xhtml in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.10 does not properly handle attempted clickjacking of the… | |
| Modificada | Media (4.3) | 1.6% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRMozilla Seamonkey | 18/7/2012 | 16/6/2026 | The Content Security Policy (CSP) functionality in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly restrict the strings placed into the blocked-uri parameter of a violation report, which… | |
| Modificada | Alta (10) | 5.6% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRMozilla Seamonkey | 18/7/2012 | 16/6/2026 | Use-after-free vulnerability in the JSDependentString::undepend function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (memory corruption) or possibly… | |
| Modificada | Media (4.3) | 2.1% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRMozilla Seamonkey | 18/7/2012 | 16/6/2026 | Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly handle duplicate values in X-Frame-Options headers, which makes it easier for remote attackers to conduct clickjacking attacks via a FRAME… | |
| Modificada | Media (5) | 1.8% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Seamonkey | 18/7/2012 | 16/6/2026 | The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through 13.0, and SeaMonkey before 2.11 might allow remote attackers to obtain sensitive information from process memory via a crafted color profile that triggers an out-of-bounds read… | |
| Modificada | Media (5) | 2.5% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRMozilla Seamonkey | 18/7/2012 | 16/6/2026 | Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not consider the presence of same-compartment security wrappers (SCSW) during the cross-compartment wrapping of objects, which allows remote attackers to… | |
| Modificada | Alta (9.3) | 4.8% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRMozilla Seamonkey | 18/7/2012 | 16/6/2026 | Use-after-free vulnerability in the nsGlobalWindow::PageHidden function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 might allow remote attackers to execute arbitrary code via vectors related to focused… | |
| Modificada | Media (4.3) | 2.1% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRMozilla Seamonkey | 18/7/2012 | 16/6/2026 | An unspecified parser-utility class in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly handle EMBED elements within description elements in RSS feeds, which allows remote attackers to conduct… | |
| Modificada | Media (6.8) | 2.3% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRMozilla Seamonkey | 18/7/2012 | 16/6/2026 | Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allow remote attackers to spoof the address bar via vectors involving history.forward and history.back calls. | |
| Modificada | Alta (10) | 4.4% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRMozilla Seamonkey | 18/7/2012 | 16/6/2026 | Use-after-free vulnerability in the nsDocument::AdoptNode function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption) or possibly… | |
| Modificada | Alta (9.3) | 4.3% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRMozilla Seamonkey | 18/7/2012 | 16/6/2026 | The ElementAnimations::EnsureStyleRuleFor function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (buffer over-read, incorrect pointer dereference, and… | |
| Modificada | Alta (9.3) | 3.7% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRMozilla Seamonkey | 18/7/2012 | 16/6/2026 | The nsTableFrame::InsertFrames function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly perform a cast of a frame variable during processing of mixed row-group and column-group frames,… | |
| Modificada | Alta (10) | 5.5% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRMozilla Seamonkey | 18/7/2012 | 16/6/2026 | Use-after-free vulnerability in the nsSMILTimeValueSpec::IsEventBased function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allows remote attackers to cause a denial of service (heap memory corruption)… | |
| Modificada | Alta (9.3) | 4.8% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Seamonkey | 18/7/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through 13.0, and SeaMonkey before 2.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | |
| Modificada | Alta (9.3) | 4.8% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRMozilla Seamonkey | 18/7/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or… | |
| Modificada | Alta (7.5) | 1.9% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 18/6/2012 | 16/6/2026 | Use-after-free vulnerability in the nsHTMLSelectElement function in nsHTMLSelectElement.cpp in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allows remote attackers to execute arbitrary code via vectors involving removal of the parent node of an element. | |
| Modificada | Alta (9.3) | 3.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR | 5/6/2012 | 16/6/2026 | The glBufferData function in the WebGL implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not properly mitigate an unspecified flaw in an NVIDIA driver, which allows remote attackers to… | |
| Modificada | Alta (9.3) | 4.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR | 5/6/2012 | 16/6/2026 | Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set… |