Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
718 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 5.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 2/3/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | |
| Modificada | Media (6.8) | 1.8% | — | Mozilla FirefoxMozilla Seamonkey | 2/3/2011 | 16/6/2026 | Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, does not properly handle certain recursive eval calls, which makes it easier for remote attackers to force a user to respond positively to a dialog question, as demonstrated by a question about granting privileges. | |
| Modificada | Alta (9.3) | 8.1% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Seamonkey | 10/12/2010 | 16/6/2026 | Unspecified vulnerability in Mozilla Firefox 3.5.x before 3.5.16, Thunderbird before 3.0.11, and SeaMonkey before 2.0.11 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | |
| Modificada | Alta (9.3) | 8.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 10/12/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary… | |
| Modificada | Alta (9.3) | 3.8% | — | Mozilla FirefoxMozilla Seamonkey | 10/12/2010 | 16/6/2026 | Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle certain redirections involving data: URLs and Java LiveConnect scripts, which allows remote attackers to start processes, read arbitrary local files, and establish network connections via vectors involving a… | |
| Modificada | Media (4.3) | 1.6% | — | Mozilla FirefoxMozilla Seamonkey | 10/12/2010 | 16/6/2026 | The NS_SecurityCompareURIs function in netwerk/base/public/nsNetUtil.h in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle (1) about:neterror and (2) about:certerror pages, which allows remote attackers to spoof the location bar via a crafted web site. | |
| Modificada | Media (6.8) | 3.1% | — | Mozilla FirefoxMozilla Seamonkey | 10/12/2010 | 16/6/2026 | Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via… | |
| Modificada | Alta (9.3) | 4.8% | — | Mozilla FirefoxMozilla Seamonkey | 10/12/2010 | 16/6/2026 | Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly calculate index values for certain child content in a XUL tree, which allows remote attackers to execute arbitrary code via vectors involving a DIV element within a treechildren element. | |
| Modificada | Media (6.8) | 2.3% | — | Mozilla FirefoxMozilla Seamonkey | 10/12/2010 | 16/6/2026 | Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle injection of an ISINDEX element into an about:blank page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to redirection to a chrome: URI. | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Mozilla FirefoxMozilla Seamonkey | 10/12/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allow remote attackers to inject arbitrary web script or HTML via (1) x-mac-arabic, (2) x-mac-farsi, or (3) x-mac-hebrew characters that may be converted to… | |
| Modificada | Alta (9.3) | 4.6% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Seamonkey | 10/12/2010 | 16/6/2026 | The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that… | |
| Modificada | Alta (9.3) | 4.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 10/12/2010 | 16/6/2026 | Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 do not properly validate downloadable fonts before use within an operating system's font implementation, which allows remote attackers to execute arbitrary code via vectors related to… | |
| Modificada | Alta (9.3) | 4.8% | — | Mozilla FirefoxMozilla Seamonkey | 10/12/2010 | 16/6/2026 | Integer overflow in the NewIdArray function in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via a JavaScript array with many elements. | |
| Modificada | Alta (9.3) | 7.0% | — | Mozilla FirefoxMozilla Seamonkey | 10/12/2010 | 16/6/2026 | Use-after-free vulnerability in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via vectors involving a change to an nsDOMAttribute node. | |
| Analizada | Crítica (9.8) | 83% | ⚠ Explotación activa💥 Exploit | Mozilla FirefoxMozilla ThunderbirdMozilla Seamonkey | 28/10/2010 | 16/6/2026 | Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method,… | |
| Modificada | Alta (9.3) | 6.5% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | The LookupGetterOrSetter function in js3250.dll in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly support window.__lookupGetter__ function calls that lack arguments, which allows remote attackers to execute arbitrary… | |
| Modificada | Media (6.9) | 0.29% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | A certain application-launch script in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Linux places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in… | |
| Modificada | Media (6.9) | 0.27% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | Untrusted search path vulnerability in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory. | |
| Modificada | Alta (9.3) | 4.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | Use-after-free vulnerability in the nsBarProp function in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code by accessing the locationbar property of a closed window. | |
| Modificada | Alta (9.3) | 10% | 💥 Exploit | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash)… | |
| Modificada | Media (5.8) | 1.4% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 do not properly handle certain modal calls made by javascript: URLs in circumstances related to opening a new window and performing cross-domain navigation, which allows remote attackers… | |
| Modificada | Media (4.3) | 2.1% | — | Mozilla FirefoxMozilla Seamonkey | 21/10/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Gopher parser in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, and SeaMonkey before 2.0.9, allow remote attackers to inject arbitrary web script or HTML via a crafted name of a (1) file or (2) directory on a Gopher server. | |
| Modificada | Alta (9.3) | 4.5% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute… | |
| Modificada | Alta (9.3) | 3.0% | — | Mozilla SeamonkeyMozilla FirefoxMozilla Thunderbird | 21/10/2010 | 16/6/2026 | Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.14, Thunderbird before 3.0.9, and SeaMonkey before 2.0.9 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.5) | 3.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic… |