Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
718 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 5.6% | — | Mozilla SeamonkeyMozilla FirefoxMozilla Thunderbird | 30/6/2011 | 16/6/2026 | Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via a crafted XUL document that dequeues the current command updater. | |
| Modificada | Alta (10) | 5.8% | — | Mozilla SeamonkeyMozilla FirefoxMozilla Thunderbird | 30/6/2011 | 16/6/2026 | Use-after-free vulnerability in the nsSVGPathSegList::ReplaceItem function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via… | |
| Modificada | Alta (10) | 5.5% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 7/5/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown… | |
| Modificada | Alta (10) | 5.3% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 7/5/2011 | 16/6/2026 | Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a… | |
| Modificada | Alta (10) | 5.3% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 7/5/2011 | 16/6/2026 | Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a… | |
| Modificada | Alta (7.5) | 1.8% | — | Mozilla FirefoxMozilla Seamonkey | 7/5/2011 | 16/6/2026 | Unspecified vulnerability in the Java Embedding Plugin (JEP) in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, on Mac OS X allows remote attackers to bypass intended access restrictions via unknown vectors. | |
| Modificada | Alta (10) | 5.3% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 7/5/2011 | 16/6/2026 | Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a… | |
| Modificada | Alta (10) | 5.3% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 7/5/2011 | 16/6/2026 | Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a… | |
| Modificada | Alta (10) | 70% | 💥 Exploit | Mozilla FirefoxMozilla Seamonkey | 7/5/2011 | 16/6/2026 | Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer." | |
| Modificada | Alta (10) | 5.3% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 7/5/2011 | 16/6/2026 | Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a… | |
| Modificada | Media (5) | 2.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 7/5/2011 | 16/6/2026 | Directory traversal vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 on Windows allows remote attackers to determine the existence of arbitrary files, and possibly load resources, via vectors involving a resource: URL. | |
| Modificada | Alta (10) | 6.9% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 7/5/2011 | 16/6/2026 | Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via… | |
| Modificada | Alta (10) | 6.9% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 7/5/2011 | 16/6/2026 | Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via… | |
| Modificada | Media (5) | 2.2% | — | Mozilla FirefoxMozilla Seamonkey | 7/5/2011 | 16/6/2026 | Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly implement autocompletion for forms, which allows remote attackers to read form history entries via a Java applet that spoofs interaction with the autocomplete controls. | |
| Modificada | Alta (10) | 4.8% | — | Mozilla FirefoxMozilla Seamonkey | 7/5/2011 | 16/6/2026 | Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mObserverList. | |
| Modificada | Alta (10) | 74% | 💥 Exploit | Mozilla FirefoxMozilla Seamonkey | 7/5/2011 | 16/6/2026 | Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mChannel. | |
| Modificada | Media (4.3) | 1.1% | — | Mozilla FirefoxMozilla Seamonkey | 15/4/2011 | 16/6/2026 | The txXPathNodeUtils::getXSLTId function in txMozillaXPathTreeWalker.cpp and txStandaloneXPathTreeWalker.cpp in Mozilla Firefox before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1, and SeaMonkey before 2.0.14, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an… | |
| Modificada | Media (5) | 1.6% | — | Google ChromeMozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 11/3/2011 | 16/6/2026 | Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak." | |
| Modificada | Alta (9.3) | 4.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 2/3/2011 | 16/6/2026 | Buffer overflow in Mozilla Firefox 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image. | |
| Modificada | Media (6.8) | 0.97% | — | Mozilla FirefoxMozilla Seamonkey | 2/3/2011 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated by a plugin and received a 307 redirect to a page on a different web site. | |
| Modificada | Alta (10) | 5.5% | — | Mozilla FirefoxMozilla Seamonkey | 2/3/2011 | 16/6/2026 | Buffer overflow in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a long string that triggers construction of a long text run. | |
| Modificada | Alta (10) | 4.7% | — | Mozilla FirefoxMozilla Seamonkey | 2/3/2011 | 16/6/2026 | Use-after-free vulnerability in the Web Workers implementation in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to execute arbitrary code via vectors related to a JavaScript Worker and garbage collection. | |
| Modificada | Alta (10) | 4.6% | — | Mozilla FirefoxMozilla Seamonkey | 2/3/2011 | 16/6/2026 | Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via vectors involving exception timing and a large number of string values, aka an "atom map" issue. | |
| Modificada | Alta (10) | 7.2% | — | Mozilla FirefoxMozilla Seamonkey | 2/3/2011 | 16/6/2026 | Use-after-free vulnerability in the JSON.stringify method in js3250.dll in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via unspecified vectors related to the js_HasOwnProperty function and garbage collection. | |
| Modificada | Alta (10) | 4.6% | — | Mozilla FirefoxMozilla Seamonkey | 2/3/2011 | 16/6/2026 | Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via vectors involving non-local JavaScript variables, aka an "upvarMap" issue. |