Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
772 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.6) | 3.4% | — | Mozilla FirefoxMozilla Seamonkey | 5/4/2010 | 16/6/2026 | Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mouse clicks as drag-and-drop actions, which allows remote attackers to execute arbitrary JavaScript with Chrome privileges by loading a chrome: URL and then loading a… | |
| Modificada | Alta (9.3) | 6.9% | — | Mozilla FirefoxMozilla Seamonkey | 5/4/2010 | 16/6/2026 | Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, frees the contents of the window.navigator.plugins array while a reference to an array element is still active, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash)… | |
| Modificada | Alta (9.3) | 5.2% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Seamonkey | 5/4/2010 | 16/6/2026 | Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execute arbitrary code via unspecified vectors that trigger access to… | |
| Modificada | Alta (9.3) | 7.0% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Seamonkey | 5/4/2010 | 16/6/2026 | Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call… | |
| Modificada | Alta (10) | 5.9% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Seamonkey | 5/4/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code… | |
| Modificada | Alta (9.3) | 4.5% | — | Mozilla FirefoxMozilla ThunderbirdMozilla Seamonkey | 5/4/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | |
| Modificada | Media (5.8) | 2.0% | — | Mozilla FirefoxMozilla Seamonkey | 26/3/2010 | 16/6/2026 | The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls to the focus method. | |
| Modificada | Media (4.3) | 1.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 25/3/2010 | 16/6/2026 | Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allow remote attackers to perform cross-origin keystroke capture, and possibly conduct cross-site scripting (XSS) attacks, by using the addEventListener and setTimeout functions in… | |
| Modificada | Media (5) | 1.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 25/3/2010 | 16/6/2026 | The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which… | |
| Modificada | Alta (9.3) | 10% | 💥 Exploit | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 25/3/2010 | 16/6/2026 | The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1)… | |
| Modificada | Media (4.3) | 3.2% | — | Mozilla ThunderbirdMozilla Seamonkey | 23/3/2010 | 16/6/2026 | Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process e-mail attachments with a parser that performs casts and line termination incorrectly, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted message, related to message… | |
| Modificada | Media (4.3) | 1.7% | — | Mozilla ThunderbirdMozilla Seamonkey | 23/3/2010 | 16/6/2026 | The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 on Windows Vista, Windows Server 2008 R2, and Windows 7 allows remote SMTP, IMAP, and POP servers to cause a denial of service (heap memory corruption and application crash) or possibly… | |
| Modificada | Alta (7.1) | 2.8% | — | Mozilla Seamonkey | 23/3/2010 | 16/6/2026 | The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted remote attackers to obtain sensitive information via crafted content in an IFRAME element in an HTML e-mail message, as demonstrated by a Flash object that sends arbitrary… | |
| Modificada | Media (4.3) | 2.9% | — | Mozilla FirefoxMozilla Seamonkey | 22/2/2010 | 16/6/2026 | Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly support the application/octet-stream content type as a protection mechanism against execution of web script in certain circumstances involving SVG and the EMBED element, which allows remote attackers to bypass the… | |
| Modificada | Alta (10) | 6.0% | — | Mozilla FirefoxMozilla Seamonkey | 22/2/2010 | 16/6/2026 | The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary… | |
| Modificada | Alta (10) | 4.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+1 | 22/2/2010 | 16/6/2026 | The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame… | |
| Modificada | Media (5) | 2.1% | — | Mozilla FirefoxMozilla Seamonkey | 22/2/2010 | 16/6/2026 | Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values. | |
| Modificada | Alta (10) | 6.5% | — | Mozilla FirefoxMozilla Seamonkey | 22/2/2010 | 16/6/2026 | Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations. | |
| Modificada | Media (4.3) | 1.9% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 18/2/2010 | 16/6/2026 | Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote… | |
| Modificada | Media (5) | 1.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 29/1/2010 | 16/6/2026 | Mozilla Necko, as used in Firefox, SeaMonkey, and other applications, performs DNS prefetching of domain names contained in links within local HTML documents, which makes it easier for remote attackers to determine the network location of the application's user by logging DNS requests. NOTE: the vendor disputes the… | |
| Modificada | Media (5) | 0.93% | — | Mozilla SeamonkeyMozilla Thunderbird | 29/1/2010 | 16/6/2026 | Mozilla Necko, as used in Thunderbird 3.0.1, SeaMonkey, and other applications, performs DNS prefetching even when the app type is APP_TYPE_MAIL or APP_TYPE_EDITOR, which makes it easier for remote attackers to determine the network location of the application's user by logging DNS requests, as demonstrated by DNS… | |
| Modificada | Alta (7.8) | 1.6% | — | Mozilla FirefoxMozilla Seamonkey | 17/12/2009 | 16/6/2026 | The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed… | |
| Modificada | Alta (7.6) | 3.7% | — | Mozilla FirefoxMozilla Seamonkey | 17/12/2009 | 16/6/2026 | Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window.opener property. | |
| Modificada | Media (6.8) | 2.5% | — | Mozilla FirefoxMozilla Seamonkey | 17/12/2009 | 16/6/2026 | Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654. | |
| Modificada | Media (6.8) | 2.2% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 17/12/2009 | 16/6/2026 | Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body. |