CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11793  CVE-2005-0587  Candidate  Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.  Assigned (20050228)  None (candidate not yet proposed)    View
11794  CVE-2005-0588  Candidate  Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.  Assigned (20050228)  None (candidate not yet proposed)    View
11795  CVE-2005-0589  Candidate  The Form Fill feature in Firefox before 1.0.1 allows remote attackers to steal potentially sensitive information via an input control that monitors the values that are generated by the autocomplete capability.  Assigned (20050228)  None (candidate not yet proposed)    View
11796  CVE-2005-0590  Candidate  The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.  Assigned (20050228)  None (candidate not yet proposed)    View
11797  CVE-2005-0591  Candidate  Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file, aka "Firespoofing."  Assigned (20050228)  None (candidate not yet proposed)    View

Page 19691 of 20943, showing 5 records out of 104715 total, starting on record 98451, ending on 98455

Actions