|
231
|
-
5.0
|
MEDIUM
|
Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain t…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2014-1483
|
cpe:2.3:o:suse:linux_enterprise_server:11:sp3 cpe:2.3:o:suse:linux_enterprise_server:11:sp3
|
|
|
|
|
2024-11-21 11:04
2014-02-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
232
|
-
4.3
|
MEDIUM
|
The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjac…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2014-1480
|
cpe:2.3:o:suse:linux_enterprise_server:11:sp3 cpe:2.3:o:suse:linux_enterprise_server:11:sp3
|
|
|
|
|
2024-11-21 11:04
2014-02-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
233
|
-
6.8
|
MEDIUM
|
libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote at…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0339
|
cpe:2.3:o:suse:linux_enterprise_server:10:sp4
|
|
|
|
|
2024-11-21 10:47
2014-01-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
234
|
-
5.0
|
MEDIUM
|
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (cra…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-4458
|
cpe:2.3:o:suse:linux_enterprise_server:11:sp2
|
|
|
|
|
2024-11-21 10:55
2013-12-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
235
|
5.9
4.3
|
MEDIUM
Network
|
Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of trust from an EV X.509 certificate, which makes it e…
|
CWE-310
Cryptographic Issues
|
CVE-2013-6673
|
cpe:2.3:o:suse:linux_enterprise_server:11:sp3 cpe:2.3:o:suse:linux_enterprise_server:11:sp3
|
|
|
|
|
2024-11-21 10:59
2013-12-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
236
|
-
4.3
|
MEDIUM
|
Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers to read clipboard data by leveraging certain middle-click paste operations.
|
CWE-200
Information Exposure
|
CVE-2013-6672
|
cpe:2.3:o:suse:linux_enterprise_server:11:sp3 cpe:2.3:o:suse:linux_enterprise_server:11:sp3
|
|
|
|
|
2024-11-21 10:59
2013-12-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
237
|
-
7.5
|
HIGH
|
Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote attackers to cause a denial of service (out-…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2013-5619
|
cpe:2.3:o:suse:linux_enterprise_server:11:sp3 cpe:2.3:o:suse:linux_enterprise_server:11:sp3
|
|
|
|
|
2024-11-21 10:57
2013-12-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
238
|
-
4.3
|
MEDIUM
|
Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attacker…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2013-5614
|
cpe:2.3:o:suse:linux_enterprise_server:11:sp3 cpe:2.3:o:suse:linux_enterprise_server:11:sp3
|
|
|
|
|
2024-11-21 10:57
2013-12-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
239
|
-
4.3
|
MEDIUM
|
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging a Same Orig…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5612
|
cpe:2.3:o:suse:linux_enterprise_server:11:sp3 cpe:2.3:o:suse:linux_enterprise_server:11:sp3
|
|
|
|
|
2024-11-21 10:57
2013-12-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
240
|
-
5.8
|
MEDIUM
|
Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing…
|
NVD-CWE-noinfo
|
CVE-2013-5611
|
cpe:2.3:o:suse:linux_enterprise_server:11:sp3 cpe:2.3:o:suse:linux_enterprise_server:11:sp3
|
|
|
|
|
2024-11-21 10:57
2013-12-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|