Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
704 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 9/9/2010 | 16/6/2026 | Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict read access to the statusText property of XMLHttpRequest objects, which allows remote attackers to discover the existence of intranet web servers via cross-origin… | |
| Modificada | Media (4.3) | 1.6% | — | Mozilla SeamonkeyMozilla ThunderbirdMozilla Firefox | 9/9/2010 | 16/6/2026 | The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting… | |
| Modificada | Alta (9.3) | 4.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 9/9/2010 | 16/6/2026 | Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via vectors involving a XUL tree selection, related to a "dangling… | |
| Modificada | Alta (9.3) | 23% | 💥 Exploit | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 26/8/2010 | 16/6/2026 | Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse… | |
| Modificada | Alta (8.8) | 6.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdOpensuse+3 | 30/7/2010 | 16/6/2026 | Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free. | |
| Modificada | Alta (9.3) | 9.8% | 💥 Exploit | Mozilla FirefoxMozilla ThunderbirdMozilla Seamonkey | 30/7/2010 | 16/6/2026 | Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code by placing many Cascading Style Sheets (CSS) values in an array, related to references to… | |
| Modificada | Baja (2.6) | 1.9% | — | Mozilla FirefoxMozilla Seamonkey | 30/7/2010 | 16/6/2026 | The nsDocShell::OnRedirectStateChange function in docshell/base/nsDocShell.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to spoof the SSL security status of a document via vectors involving multiple requests, a redirect, and the history.back and… | |
| Modificada | Alta (9.3) | 7.6% | 💥 Exploit | Mozilla FirefoxMozilla Seamonkey | 30/7/2010 | 16/6/2026 | Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via plugin content with many parameter elements. | |
| Modificada | Media (4.3) | 0.96% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Seamonkey | 30/7/2010 | 16/6/2026 | The importScripts Web Worker method in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not verify that content is valid JavaScript code, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive… | |
| Modificada | Alta (9.3) | 3.7% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Seamonkey | 30/7/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute… | |
| Modificada | Alta (9.3) | 5.4% | — | Mozilla FirefoxMozilla Seamonkey | 30/7/2010 | 16/6/2026 | Use-after-free vulnerability in the NodeIterator implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via a crafted NodeFilter that detaches DOM nodes, related to the NodeIterator interface and a javascript callback. | |
| Modificada | Alta (8.8) | 5.2% | — | Mozilla FirefoxMozilla Seamonkey | 30/7/2010 | 16/6/2026 | Use-after-free vulnerability in the attribute-cloning functionality in the DOM implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via vectors related to deletion of an event attribute node with a nonzero reference… | |
| Modificada | Media (5) | 1.1% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Seamonkey | 30/7/2010 | 16/6/2026 | dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not properly suppress a script's URL in certain circumstances involving a redirect and an error message, which allows remote attackers to… | |
| Modificada | Crítica (9.8) | 43% | 💥 Exploit | LibpngGoogle ChromeApple ItunesApple Safari+13 | 30/6/2010 | 16/6/2026 | Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row. | |
| Modificada | Media (4.3) | 1.1% | — | Mozilla FirefoxMozilla Seamonkey | 25/6/2010 | 16/6/2026 | The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading, which… | |
| Modificada | Alta (9.3) | 4.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 24/6/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown… | |
| Modificada | Alta (9.3) | 6.1% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 24/6/2010 | 16/6/2026 | Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.10, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | |
| Modificada | Alta (9.3) | 5.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 24/6/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown… | |
| Modificada | Alta (9.3) | 11% | 💥 Exploit | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 24/6/2010 | 16/6/2026 | Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a node. | |
| Modificada | Alta (9.3) | 4.8% | — | Mozilla FirefoxMozilla Seamonkey | 24/6/2010 | 16/6/2026 | Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to execute arbitrary code via vectors involving multiple plugin instances. | |
| Modificada | Media (4.3) | 2.1% | — | Mozilla FirefoxMozilla Seamonkey | 24/6/2010 | 16/6/2026 | Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not properly handle situations in which both "Content-Disposition: attachment" and "Content-Type: multipart" are present in HTTP headers, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an… | |
| Modificada | Alta (9.3) | 4.9% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 24/6/2010 | 16/6/2026 | Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a DOM node with a long text value that triggers a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 4.0% | — | Mozilla FirefoxMozilla Seamonkey | 24/6/2010 | 16/6/2026 | Use-after-free vulnerability in the nsCycleCollector::MarkRoots function in Mozilla Firefox 3.5.x before 3.5.10 and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a crafted HTML document, related to an improper frame construction process for menus. | |
| Modificada | Media (5) | 2.1% | — | Mozilla FirefoxMozilla Seamonkey | 20/5/2010 | 16/6/2026 | Mozilla Firefox 3.6.x, 3.5.x, 3.0.19, and earlier, and SeaMonkey, executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements. | |
| Modificada | Alta (9.3) | 4.5% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 28/4/2010 | 16/6/2026 | The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 does not properly sanitize HTML in a chrome document, which makes it easier for remote attackers to execute… |