Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
772 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 6.5% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | The LookupGetterOrSetter function in js3250.dll in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly support window.__lookupGetter__ function calls that lack arguments, which allows remote attackers to execute arbitrary… | |
| Modificada | Media (6.9) | 0.29% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | A certain application-launch script in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Linux places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in… | |
| Modificada | Media (6.9) | 0.27% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | Untrusted search path vulnerability in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory. | |
| Modificada | Alta (9.3) | 4.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | Use-after-free vulnerability in the nsBarProp function in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code by accessing the locationbar property of a closed window. | |
| Modificada | Alta (9.3) | 10% | 💥 Exploit | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash)… | |
| Modificada | Media (5.8) | 1.4% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 do not properly handle certain modal calls made by javascript: URLs in circumstances related to opening a new window and performing cross-domain navigation, which allows remote attackers… | |
| Modificada | Media (4.3) | 2.1% | — | Mozilla FirefoxMozilla Seamonkey | 21/10/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Gopher parser in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, and SeaMonkey before 2.0.9, allow remote attackers to inject arbitrary web script or HTML via a crafted name of a (1) file or (2) directory on a Gopher server. | |
| Modificada | Alta (9.3) | 4.5% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute… | |
| Modificada | Alta (9.3) | 3.0% | — | Mozilla SeamonkeyMozilla FirefoxMozilla Thunderbird | 21/10/2010 | 16/6/2026 | Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.14, Thunderbird before 3.0.9, and SeaMonkey before 2.0.9 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.5) | 3.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic… | |
| Modificada | Media (4.3) | 1.1% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2010 | 16/6/2026 | Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted… | |
| Modificada | Media (5.8) | 1.4% | — | Mozilla FirefoxMozilla Seamonkey | 15/9/2010 | 16/6/2026 | The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses the current time for seeding of a random number generator, which makes it easier for remote attackers to guess the seed value via a brute-force attack, a different… | |
| Modificada | Alta (9.3) | 3.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 9/9/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary… | |
| Modificada | Alta (9.3) | 4.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 9/9/2010 | 16/6/2026 | Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict the role of property changes in triggering XUL tree removal, which allows remote attackers to cause a denial of service (deleted memory access and application… | |
| Modificada | Alta (9.3) | 6.5% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 9/9/2010 | 16/6/2026 | The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle node removal in XUL trees, which allows remote attackers to execute arbitrary code via vectors involving access to deleted memory,… | |
| Modificada | Alta (9.3) | 5.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 9/9/2010 | 16/6/2026 | Heap-based buffer overflow in the nsTextFrameUtils::TransformText function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a bidirectional text run. | |
| Modificada | Alta (9.3) | 3.7% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Seamonkey | 9/9/2010 | 16/6/2026 | Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Mac OS X allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted font in a data: URL. | |
| Modificada | Media (4.3) | 2.1% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 9/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML via a selection that is added to a document in which the designMode… | |
| Modificada | Media (4.3) | 2.1% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 9/9/2010 | 16/6/2026 | Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict use of the type attribute of an OBJECT element to set a document's charset, which allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms… | |
| Modificada | Alta (9.3) | 4.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 9/9/2010 | 16/6/2026 | The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle destruction of the DOM plugin array, which might allow remote attackers to cause a denial of service (application crash) or… | |
| Modificada | Alta (9.3) | 5.4% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 9/9/2010 | 16/6/2026 | The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle the removal of DOM nodes during normalization, which might allow remote attackers to execute arbitrary code via vectors involving… | |
| Modificada | Alta (9.3) | 5.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 9/9/2010 | 16/6/2026 | Integer overflow in the FRAMESET element implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a large number of values in the cols (aka columns) attribute, leading… | |
| Modificada | Media (4.3) | 2.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 9/9/2010 | 16/6/2026 | Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict read access to the statusText property of XMLHttpRequest objects, which allows remote attackers to discover the existence of intranet web servers via cross-origin… | |
| Modificada | Media (4.3) | 1.6% | — | Mozilla SeamonkeyMozilla ThunderbirdMozilla Firefox | 9/9/2010 | 16/6/2026 | The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting… | |
| Modificada | Alta (9.3) | 4.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 9/9/2010 | 16/6/2026 | Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via vectors involving a XUL tree selection, related to a "dangling… |