Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
772 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 1.2% | — | Sourceforge CreammonkeySourceforge Greasekit | 4/1/2008 | 16/6/2026 | Creammonkey 0.9 through 1.1 and GreaseKit 1.2 through 1.3 does not properly prevent access to dangerous functions, which allows remote attackers to read the configuration, modify the configuration, or send an HTTP request via the (1) GM_addStyle, (2) GM_log, (3) GM_openInTab, (4) GM_setValue, (5) GM_getValue, or (6)… | |
| Modificada | Media (4.3) | 1.1% | — | Mozilla FirefoxMozilla Seamonkey | 28/12/2007 | 16/6/2026 | The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI, a different vulnerability than… | |
| Modificada | Media (4.3) | 1.5% | — | Mozilla FirefoxMozilla Seamonkey | 26/11/2007 | 16/6/2026 | Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting… | |
| Modificada | Alta (9.3) | 5.4% | — | Mozilla FirefoxMozilla Seamonkey | 26/11/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger memory corruption. | |
| Modificada | Media (4.3) | 2.7% | — | Mozilla FirefoxMozilla Seamonkey | 14/11/2007 | 16/6/2026 | The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar:… | |
| Modificada | Alta (9.3) | 3.2% | — | Mozilla FirefoxMozilla Seamonkey | 21/10/2007 | 16/6/2026 | Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Script object to modify XPCNativeWrappers in a way that causes the script to be executed when a chrome action is performed. | |
| Modificada | Media (4.3) | 2.4% | — | Gnome-vfsMozilla FirefoxMozilla Seamonkey | 21/10/2007 | 16/6/2026 | Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2)… | |
| Modificada | Media (4.3) | 3.0% | — | Mozilla FirefoxMozilla Seamonkey | 21/10/2007 | 16/6/2026 | Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displaying XUL markup language documents, which makes it easier for remote attackers to conduct phishing and spoofing attacks by setting the hidechrome attribute. | |
| Modificada | Media (4.3) | 3.4% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2007 | 16/6/2026 | Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption or assert errors. | |
| Modificada | Media (4.3) | 3.4% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 21/10/2007 | 16/6/2026 | Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption. | |
| Modificada | Media (5) | 1.3% | — | Mozilla FirefoxMozilla Seamonkey | 13/9/2007 | 16/6/2026 | Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates with minimal user interaction, and automatically sends these certificates when requested, which makes it easier for remote web sites to track user activities across domains by requesting the TLS… | |
| Modificada | Alta (9.3) | 2.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 12/9/2007 | 16/6/2026 | Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execute arbitrary commands via a (1) mailto, (2) nntp, (3) news, or (4) snews URI with invalid "%" encoding, related to improper file type handling on Windows XP with Internet Explorer 7 installed, a… | |
| Modificada | Media (4.3) | 5.4% | 💥 Exploit | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 8/8/2007 | 16/6/2026 | Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function… | |
| Modificada | Alta (9.3) | 5.7% | 💥 Exploit | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 8/8/2007 | 16/6/2026 | Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbitrary commands via certain vectors associated with launching "a file handling program based on the file extension at the end of the URI," a variant of CVE-2007-4041.… | |
| Modificada | Media (4.3) | 6.7% | — | Microsoft Internet ExplorerMozilla Seamonkey | 24/7/2007 | 16/6/2026 | Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with SeaMonkey installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a mailto URI, which are inserted into the command… | |
| Modificada | Media (4.3) | 2.4% | — | Mozilla FirefoxMozilla Seamonkey | 3/7/2007 | 16/6/2026 | The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from… | |
| Modificada | Media (4.3) | 1.6% | — | Mozilla FirefoxMozilla Seamonkey | 1/6/2007 | 16/6/2026 | Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to bypass the same-origin policy and conduct cross-site scripting (XSS) and other attacks by using the addEventListener method to add an event listener for a site, which is executed in the context of… | |
| Modificada | Media (4.3) | 2.5% | — | Mozilla FirefoxMozilla Seamonkey | 1/6/2007 | 16/6/2026 | Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to spoof or hide the browser chrome, such as the location bar, by placing XUL popups outside of the browser's content pane. NOTE: this issue can be leveraged for phishing and other attacks. | |
| Modificada | Alta (9.3) | 3.4% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 1/6/2007 | 16/6/2026 | Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of service (crash) via vectors related to dangling pointers, heap corruption,… | |
| Modificada | Media (4.3) | 7.8% | 💥 Exploit | Mozilla FirefoxMozilla Seamonkey | 1/6/2007 | 16/6/2026 | Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to cause a denial of service via (1) a large cookie path parameter, which triggers memory consumption, or (2) an internal delimiter within cookie path or name values, which could trigger a… | |
| Modificada | Alta (9.3) | 4.9% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 1/6/2007 | 16/6/2026 | Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that… | |
| Modificada | Media (4.3) | 13% | — | Microsoft Internet ExplorerMozilla FirefoxMozilla Seamonkey | 26/4/2007 | 16/6/2026 | CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF (%0a) bytes in the username attribute. | |
| Modificada | Alta (7.5) | 1.5% | — | Monkey CMS | 18/4/2007 | 16/6/2026 | Directory traversal vulnerability in admin/index.php in Monkey CMS 0.0.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the admin_skin parameter. | |
| Modificada | Alta (9.3) | 4.7% | — | Mozilla SeamonkeyMozilla Thunderbird | 6/3/2007 | 16/6/2026 | Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly execute arbitrary code via a text/enhanced or text/richtext e-mail message with an extremely long line. | |
| Modificada | Media (6.8) | 3.3% | — | Mozilla FirefoxMozilla SeamonkeyDebian Linux | 6/3/2007 | 16/6/2026 | A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access… |