|
289761
|
- |
|
yukihiro_matsumoto
|
ruby
|
The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessi…
|
NVD-CWE-Other
|
CVE-2004-0755
|
2017-10-11 10:29 |
2004-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289762
|
- |
|
mozilla
|
firefox mozilla thunderbird
|
Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2004-0757
|
2017-10-11 10:29 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289763
|
- |
|
mozilla
|
mozilla
|
Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allows remote attackers to cause a denial of service t…
|
NVD-CWE-Other
|
CVE-2004-0758
|
2017-10-11 10:29 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289764
|
- |
|
mozilla
|
mozilla
|
Mozilla before 1.7 allows remote web servers to read arbitrary files via Javascript that sets the value of an <input type="file"> tag.
|
NVD-CWE-Other
|
CVE-2004-0759
|
2017-10-11 10:29 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289765
|
- |
|
mozilla
|
mozilla
|
Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI.
|
NVD-CWE-Other
|
CVE-2004-0760
|
2017-10-11 10:29 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289766
|
- |
|
mozilla
|
firefox mozilla thunderbird
|
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypt…
|
NVD-CWE-Other
|
CVE-2004-0761
|
2017-10-11 10:29 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289767
|
- |
|
mozilla
|
firefox mozilla thunderbird
|
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.
|
NVD-CWE-Other
|
CVE-2004-0762
|
2017-10-11 10:29 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289768
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunload" method.
|
NVD-CWE-Other
|
CVE-2004-0763
|
2017-10-11 10:29 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289769
|
- |
|
mozilla
|
firefox mozilla thunderbird
|
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files.
|
NVD-CWE-Other
|
CVE-2004-0764
|
2017-10-11 10:29 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289770
|
- |
|
mozilla
|
firefox mozilla thunderbird
|
The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a f…
|
NVD-CWE-Other
|
CVE-2004-0765
|
2017-10-11 10:29 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|