Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
772 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 4.8% | — | Mozilla FirefoxMozilla Seamonkey | 13/11/2008 | 16/6/2026 | Mozilla Firefox 2.x before 2.0.0.18 and SeaMonkey 1.x before 1.1.13 do not properly check when the Flash module has been dynamically unloaded properly, which allows remote attackers to execute arbitrary code via a crafted SWF file that "dynamically unloads itself from an outside JavaScript function," which triggers an… | |
| Modificada | Media (5) | 2.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 13/11/2008 | 16/6/2026 | Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly change the source URI when processing a canvas element and an HTTP redirect, which allows remote attackers to bypass the same origin policy and access arbitrary images that are not directly accessible… | |
| Modificada | Alta (9.3) | 7.7% | — | Mozilla FirefoxMozilla SeamonkeyCanonical Ubuntu LinuxDebian Linux | 13/11/2008 | 16/6/2026 | The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response… | |
| Modificada | Media (4.3) | 10% | 💥 Exploit | Debian LinuxMozilla FirefoxCanonical Ubuntu LinuxMozilla Seamonkey | 15/10/2008 | 16/6/2026 | Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML… | |
| Modificada | Alta (10) | 7.4% | — | Mozilla SeamonkeyMozilla Thunderbird | 27/9/2008 | 16/6/2026 | Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long header in a news article, related to "canceling [a] newsgroup message" and "cancelled newsgroup messages." | |
| Modificada | Media (5) | 1.7% | — | Mozilla FirefoxMozilla Seamonkey | 24/9/2008 | 16/6/2026 | The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted XBM image file. | |
| Modificada | Alta (7.8) | 4.2% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+1 | 24/9/2008 | 16/6/2026 | Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via… | |
| Modificada | Media (4.3) | 4.4% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+1 | 24/9/2008 | 16/6/2026 | Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 on Linux allows remote attackers to read arbitrary files via a .. (dot dot) and URL-encoded / (slash) characters in a resource: URI. | |
| Modificada | Media (4.3) | 4.1% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+1 | 24/9/2008 | 16/6/2026 | Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) characters that are removed from JavaScript code before execution, aka… | |
| Modificada | Alta (10) | 5.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+1 | 24/9/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript… | |
| Modificada | Alta (10) | 5.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+1 | 24/9/2008 | 16/6/2026 | Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via an mtd element with a large… | |
| Modificada | Alta (7.5) | 4.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 24/9/2008 | 16/6/2026 | Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2)… | |
| Modificada | Alta (7.5) | 5.1% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+1 | 24/9/2008 | 16/6/2026 | The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to (1) chrome XBL and (2) chrome JS. | |
| Modificada | Alta (9.3) | 3.3% | — | Mozilla FirefoxMozilla SeamonkeyDebian LinuxCanonical Ubuntu Linux | 24/9/2008 | 16/6/2026 | Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of… | |
| Modificada | Alta (7.5) | 2.1% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 24/9/2008 | 16/6/2026 | The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors. | |
| Modificada | Alta (10) | 44% | 💥 Exploit | Mozilla FirefoxMozilla Seamonkey | 24/9/2008 | 16/6/2026 | Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link. | |
| Modificada | Media (4) | 1.2% | — | Mozilla FirefoxMozilla GeckbMozilla SeamonkeyNetscape Navigator | 8/7/2008 | 16/6/2026 | Mozilla 1.9 M8 and earlier, Mozilla Firefox 2 before 2.0.0.15, SeaMonkey 1.1.5 and other versions before 1.1.10, Netscape 9.0, and other Mozilla-based web browsers, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regard the certificate as also accepted for all domain… | |
| Modificada | Media (5) | 2.2% | — | Mozilla FirefoxMozilla Seamonkey | 7/7/2008 | 16/6/2026 | Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to force the upload of arbitrary local files from a client computer via vectors involving originalTarget and DOM Range. | |
| Modificada | Alta (10) | 14% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 7/7/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors related to the layout engine. | |
| Modificada | Media (4.3) | 2.0% | — | Mozilla FirefoxMozilla Seamonkey | 7/7/2008 | 16/6/2026 | Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors involving (1) an event handler attached to an outer window, (2) a SCRIPT element in an unloaded document, or (3) the onreadystatechange handler… | |
| Modificada | Media (6.8) | 1.1% | — | Mozilla FirefoxMozilla Seamonkey | 7/7/2008 | 16/6/2026 | Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly identify the context of Windows shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site for which the user has previously saved a shortcut. | |
| Modificada | Alta (10) | 5.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 7/7/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors related to the JavaScript engine. | |
| Modificada | Alta (7.5) | 2.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 7/7/2008 | 16/6/2026 | Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary socket connections via a crafted Java applet, related to the Java Embedding Plugin (JEP) and Java LiveConnect. | |
| Modificada | Alta (10) | 7.1% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 7/7/2008 | 16/6/2026 | The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose display requires more pixels than nscoord_MAX, related to… | |
| Modificada | Media (4.3) | 1.3% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 7/7/2008 | 16/6/2026 | Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// URLs in directory listings, which allows remote attackers to conduct cross-site scripting (XSS) attacks or have unspecified other impact via a crafted filename. |