Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

772 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.8)2.1%—Mozilla FirefoxMozilla Seamonkey27/2/200716/6/2026
The child frames in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 inherit the default charset from the parent window, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.
ModificadaMedia (6.8)2.6%—Mozilla FirefoxMozilla SeamonkeyCanonical Ubuntu Linux26/2/200716/6/2026
browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with…
ModificadaMedia (6.8)51%—Mozilla FirefoxMozilla Network Security ServicesMozilla SeamonkeyMozilla Thunderbird+226/2/200716/6/2026
Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute…
ModificadaMedia (6.4)1.6%—Mozilla FirefoxMozilla Seamonkey26/2/200716/6/2026
GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 allows remote attackers to spoof certain user interface elements, such as the host name or security indicators, via the CSS3 hotspot property with a large, transparent, custom cursor.
ModificadaMedia (5.4)3.2%—Mozilla FirefoxMozilla SeamonkeyCanonical Ubuntu LinuxDebian Linux26/2/200716/6/2026
The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is…
ModificadaMedia (6.8)4.4%—Mozilla FirefoxMozilla Network Security ServicesMozilla SeamonkeyMozilla Thunderbird26/2/200716/6/2026
Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code…
ModificadaBaja (3.7)1.1%—Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird26/2/200716/6/2026
Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allow remote attackers to cause a denial of service (crash) and potentially execute arbitrary code via certain vectors.
ModificadaAlta (9.3)6.8%—Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird26/2/200716/6/2026
Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to execute arbitrary code via a large stroke-width attribute in the clipPath element in an SVG file.
ModificadaMedia (4.3)2.2%—Mozilla FirefoxMozilla Seamonkey26/2/200716/6/2026
Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 ignores trailing invalid HTML characters in attribute names, which allows remote attackers to bypass content filters that use regular expressions.
ModificadaAlta (9.3)7.6%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux26/2/200716/6/2026
The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption.
ModificadaMedia (6.8)2.3%—Mozilla FirefoxMozilla Seamonkey26/2/200716/6/2026
Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site that is visited by a client.
ModificadaAlta (9.3)7.1%—Mozilla FirefoxMozilla Seamonkey26/2/200716/6/2026
Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize hook on DOM window objects.
ModificadaAlta (7.5)13%💥 ExploitMozilla FirefoxMozilla Seamonkey16/2/200716/6/2026
Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with…
ModificadaAlta (7.5)1.1%💥 ExploitCodemonkeyx Acronym MOD31/12/200616/6/2026
SQL injection vulnerability in admin/admin_acronyms.php in the Acronym Mod 0.9.5 for phpBB2 Plus 1.53 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (6.8)3.0%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+120/12/200616/6/2026
Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.
ModificadaMedia (6.8)4.3%—Mozilla SeamonkeyMozilla Thunderbird20/12/200616/6/2026
Multiple heap-based buffer overflows in Mozilla Thunderbird before 1.5.0.9 and SeaMonkey before 1.0.7 allow remote attackers to execute arbitrary code via (1) external message modies with long Content-Type headers or (2) long RFC2047-encoded (MIME non-ASCII) headers.
ModificadaMedia (6.8)8.6%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+120/12/200616/6/2026
Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by setting the CSS cursor to certain images that cause an incorrect size…
ModificadaMedia (6.8)4.2%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+120/12/200616/6/2026
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: URI.
ModificadaMedia (4.3)3.9%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+120/12/200616/6/2026
The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers to cause a denial of service via any plugins that reduce the…
ModificadaAlta (9.3)8.9%—Mozilla FirefoxMozilla SeamonkeyCanonical Ubuntu Linux20/12/200616/6/2026
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.
ModificadaMedia (6.8)4.4%—Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird20/12/200616/6/2026
Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown attack vectors.
ModificadaMedia (6.8)4.4%—Mozilla FirefoxMozillaMozilla ThunderbirdMozilla Seamonkey20/12/200616/6/2026
Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, SeaMonkey before 1.0.7, and Mozilla 1.7 and probably earlier on Solaris, allow remote attackers to cause a denial of service (memory corruption and crash) and possibly…
ModificadaAlta (7.1)2.4%—Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird20/12/200616/6/2026
Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) via unknown vectors.
ModificadaMedia (5)1.6%—James Greenwood Monkey Boards28/11/200616/6/2026
Monkey Boards 0.3.5 allows remote attackers to obtain sensitive information via direct requests to (1) include/admin_auth.inc.php and (2) include/engine/class.compiler.php, which reveals the full path in an error message. NOTE: this issue is only an exposure if the administrator has changed the default script path.
ModificadaAlta (7.5)2.8%—Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird8/11/200616/6/2026
Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary JavaScript bytecode via unspecified vectors involving modification of a Script object while it is executing.
Orbitaley — Vulnerabilidades