Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3146▲ 578 respecto a la semana anterior
Críticas / altas1455▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
2087 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.6) | 2.5% | — | Mozilla FirefoxMozilla SuiteMozilla SeamonkeyMozilla Thunderbird | 14/4/2006 | 16/6/2026 | Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to trick users into downloading and saving an executable file via an image that is overlaid by a transparent image link that points to the executable, which causes the executable to be… | |
| Modificada | Alta (9.3) | 8.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 14/4/2006 | 16/6/2026 | Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via "an invalid and non-sensical ordering of table-related tags" that results in a negative array index. | |
| Modificada | Baja (2.6) | 5.0% | 💥 Exploit | Mozilla Thunderbird | 7/3/2006 | 16/6/2026 | The HTML rendering engine in Mozilla Thunderbird 1.5, when "Block loading of remote images in mail messages" is enabled, does not properly block external images from inline HTML attachments, which could allow remote attackers to obtain sensitive information, such as application version or IP address, when the user… | |
| Modificada | Alta (9.3) | 7.2% | 💥 Exploit | Mozilla Thunderbird | 24/2/2006 | 16/6/2026 | The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the… | |
| Modificada | Baja (2.6) | 2.7% | 💥 Exploit | Mozilla Thunderbird | 22/2/2006 | 16/6/2026 | Mozilla Thunderbird 1.5 allows user-assisted attackers to cause an unspecified denial of service by tricking the user into importing an LDIF file with a long field into the address book, as demonstrated by a long homePhone field. | |
| Modificada | Media (6.4) | 2.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 2/2/2006 | 16/6/2026 | The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions. | |
| Modificada | Media (5.1) | 3.9% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 2/2/2006 | 16/6/2026 | Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas. | |
| Modificada | Alta (7.5) | 4.9% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 2/2/2006 | 16/6/2026 | Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory. | |
| Modificada | Media (5.1) | 71% | 💥 Exploit | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 2/2/2006 | 16/6/2026 | Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption. | |
| Modificada | Media (5.1) | 2.1% | — | Mozilla Thunderbird | 18/1/2006 | 16/6/2026 | GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large number of spaces ending with a dangerous extension that is not displayed by Thunderbird, along with an inconsistent… | |
| Modificada | Media (5) | 6.1% | 💥 Exploit | Mozilla FirefoxMozillaMozilla Thunderbird | 31/12/2005 | 16/6/2026 | Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via an A HREF tag that contains a TABLE tag that contains another A tag. | |
| Modificada | Baja (2.6) | 1.1% | — | Mozilla Thunderbird | 1/11/2005 | 16/6/2026 | The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authentication information without detection via a man-in-the-middle (MITM) attack that bypasses TLS… | |
| Modificada | Baja (2.6) | 1.7% | — | Mozilla FirefoxMozilla Thunderbird | 17/8/2005 | 16/6/2026 | Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks. | |
| Modificada | Baja (2.1) | 0.29% | — | Mozilla Thunderbird | 5/8/2005 | 16/6/2026 | run-mozilla.sh en Thunderbird, con debuggin activado, permite que usuarios locales creen o escriban en ficheros arbitrarios mediante un ataque symlink en ficheros temporales. | |
| Modificada | Alta (7.5) | 3.6% | — | Mozilla FirefoxMozillaMozilla Thunderbird | 13/7/2005 | 16/6/2026 | Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection. | |
| Modificada | Media (5) | 1.0% | — | Mozilla Thunderbird | 2/5/2005 | 16/6/2026 | Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is installed on the user's system. NOTE: since the invocation between… | |
| Modificada | Media (5) | 1.7% | — | Mozilla FirefoxMozillaMozilla Thunderbird | 2/5/2005 | 16/6/2026 | The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname. | |
| Modificada | Baja (2.1) | 0.30% | — | Mozilla FirefoxMozillaMozilla Thunderbird | 2/5/2005 | 16/6/2026 | Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF. | |
| Modificada | Media (5.1) | 15% | — | Mozilla FirefoxMozillaMozilla Thunderbird | 2/5/2005 | 16/6/2026 | Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size. | |
| Modificada | Media (5) | 4.3% | — | Mozilla FirefoxMozillaMozilla Thunderbird | 2/5/2005 | 16/6/2026 | String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by… | |
| Modificada | Media (5) | 1.7% | — | MozillaMozilla Thunderbird | 15/2/2005 | 16/6/2026 | Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail messages. | |
| Modificada | Alta (10) | 10% | — | MozillaMozilla ThunderbirdConectiva LinuxRedhat Enterprise Linux+5 | 27/1/2005 | 16/6/2026 | Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3… | |
| Modificada | Alta (10) | 9.7% | — | MozillaMozilla ThunderbirdConectiva LinuxRedhat Enterprise Linux+5 | 27/1/2005 | 16/6/2026 | Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message. | |
| Modificada | Media (4.6) | 0.42% | — | MozillaMozilla Thunderbird | 31/12/2004 | 16/6/2026 | The XPInstall installer in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 sets insecure permissions for certain installed files within xpi packages, which could allow local users to overwrite arbitrary files or execute arbitrary code. | |
| Modificada | Media (4) | 2.5% | — | MozillaMozilla Thunderbird | 31/12/2004 | 16/6/2026 | Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript code to read and write to the clipboard, and possibly obtain sensitive information, via script-generated events such as Ctrl-Ins. |