VendorsMozillafirefox3.0.1
Vulnerabilities

Mozilla Firefox 3.0.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

242CVEs
CVE-2009-0354
Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.
Published 2009-02-04 · Modified
2.6EPSS 0.023
CVE-2015-0820
Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to an extensible state, which allows remote attackers to bypass a Caja Compiler sandbox protection mechanism or a Secure EcmaScript sandbox protection mechanism via a crafted web site.
Published 2015-02-25 · Modified
2.6EPSS 0.017
← Prev7 / 7