Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

704 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.9%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+929/10/201216/6/2026
The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 does not properly determine the calling document and principal in its return value, which makes it easier for remote attackers…
ModificadaMedia (4.3)2.8%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+929/10/201216/6/2026
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 do not prevent use of the valueOf method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site…
ModificadaMedia (6.8)1.2%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+812/10/201216/6/2026
Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and…
ModificadaMedia (4.3)1.4%—Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird12/10/201216/6/2026
Mozilla Firefox 16.0, Thunderbird 16.0, and SeaMonkey 2.13 allow remote attackers to bypass the Same Origin Policy and read the properties of a Location object via a crafted web site, a related issue to CVE-2012-4193.
ModificadaAlta (9.3)3.9%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux12/10/201216/6/2026
The mozilla::net::FailDelayManager::Lookup function in the WebSockets implementation in Mozilla Firefox before 16.0.1, Thunderbird before 16.0.1, and SeaMonkey before 2.13.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified…
ModificadaMedia (6.8)1.7%—Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird10/10/201216/6/2026
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has multiple menus of SELECT elements active, which allows remote attackers to conduct clickjacking attacks via vectors involving an XPI file, the window.open method, and the…
ModificadaAlta (9.3)15%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+910/10/201216/6/2026
Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (9.3)6.8%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+810/10/201216/6/2026
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage a certain insPos variable, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and…
ModificadaAlta (9.3)15%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+910/10/201216/6/2026
Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (9.3)8.6%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+810/10/201216/6/2026
Buffer overflow in the nsCharTraits::length function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via…
ModificadaMedia (4.3)1.8%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+810/10/201216/6/2026
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not prevent access to properties of a prototype for a standard class, which allows remote attackers to execute…
ModificadaAlta (9.3)4.8%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+910/10/201216/6/2026
Use-after-free vulnerability in the DOMSVGTests::GetRequiredFeatures function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap…
ModificadaAlta (9.3)4.7%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+910/10/201216/6/2026
Use-after-free vulnerability in the nsTextEditRules::WillInsert function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory…
ModificadaAlta (9.3)4.8%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+510/10/201216/6/2026
Use-after-free vulnerability in the nsSMILAnimationController::DoSample function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap…
ModificadaAlta (9.3)9.3%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+910/10/201216/6/2026
Heap-based buffer overflow in the nsHTMLEditor::IsPrevCharInNodeWhitespace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (9.3)4.7%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+910/10/201216/6/2026
Use-after-free vulnerability in the nsHTMLCSSUtils::CreateCSSPropertyTxn function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap…
ModificadaAlta (9.3)5.0%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+810/10/201216/6/2026
The IsCSSWordSpacingSpace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
ModificadaMedia (4.3)2.4%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+810/10/201216/6/2026
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to conduct cross-site scripting (XSS) attacks via a binary plugin that uses Object.defineProperty to shadow the top object, and leverages the…
ModificadaAlta (9.3)43%💥 ExploitMozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey10/10/201216/6/2026
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not properly interact with failures of InstallTrigger methods, which allows remote attackers to execute arbitrary…
ModificadaMedia (4.3)2.5%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+810/10/201216/6/2026
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage history data, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive POST content via vectors involving a…
ModificadaAlta (9.3)3.1%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+810/10/201216/6/2026
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict JSAPI access to the GetProperty function, which allows remote attackers to bypass the Same Origin Policy and possibly have unspecified other…
ModificadaAlta (9.3)5.2%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+910/10/201216/6/2026
Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors, related to the…
ModificadaAlta (9.3)3.5%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+210/10/201216/6/2026
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly perform a cast of an unspecified variable during use of the instanceof operator on a JavaScript object, which allows remote attackers to execute arbitrary code or cause a denial of service (assertion failure) via a crafted…
ModificadaAlta (9.3)5.2%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+810/10/201216/6/2026
Use-after-free vulnerability in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 might allow user-assisted remote attackers to execute arbitrary code via vectors involving use of mozRequestFullScreen to enter full-screen…
ModificadaMedia (4.3)2.5%—Mozilla FirefoxMozilla Thunderbird ESRMozilla ThunderbirdMozilla Seamonkey+910/10/201216/6/2026
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils) methods, which allows remote attackers to bypass intended access restrictions via crafted…
Orbitaley — Vulnerabilidades