This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Summuary
CPE Namecpe:/a:mozilla:firefox:2.0
Detail
VendorMozillaFirst view 2006-10-31
ProductFirefoxLast view 2013-04-03
Version2.0TypeApplication
Edition 
Language 
Update 
 
CPE Productcpe:/a:mozilla:firefox

Activity : Yearly

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
 DateAlertAccess VectorAccess ComplexityAuthentification
102013-04-03CVE-2013-0790NetworkLowNone Requ...
102013-02-19CVE-2013-0784NetworkLowNone Requ...
102013-02-19CVE-2013-0783NetworkLowNone Requ...
102013-02-19CVE-2013-0782NetworkLowNone Requ...
102013-02-19CVE-2013-0781NetworkLowNone Requ...
Hide | Show 20 More...
 DateAlertAccess VectorAccess ComplexityAuthentification
9.32013-02-19CVE-2013-0780NetworkMediumNone Requ...
102013-02-19CVE-2013-0779NetworkLowNone Requ...
102013-02-19CVE-2013-0778NetworkLowNone Requ...
102013-02-19CVE-2013-0777NetworkLowNone Requ...
42013-02-19CVE-2013-0776NetworkHighNone Requ...
102013-02-19CVE-2013-0775NetworkLowNone Requ...
52013-02-19CVE-2013-0774NetworkLowNone Requ...
102013-02-19CVE-2013-0773NetworkLowNone Requ...
5.82013-02-19CVE-2013-0772NetworkMediumNone Requ...
52013-02-19CVE-2013-0765NetworkLowNone Requ...
9.32013-01-13CVE-2013-0771NetworkMediumNone Requ...
102013-01-13CVE-2013-0770NetworkLowNone Requ...
102013-01-13CVE-2013-0769NetworkLowNone Requ...
102013-01-13CVE-2013-0768NetworkLowNone Requ...
102013-01-13CVE-2013-0767NetworkLowNone Requ...
102013-01-13CVE-2013-0766NetworkLowNone Requ...
9.32013-01-13CVE-2013-0764NetworkMediumNone Requ...
102013-01-13CVE-2013-0763NetworkLowNone Requ...
102013-01-13CVE-2013-0762NetworkLowNone Requ...

CWE : Common Weakness Enumeration

%idName
29% (91)CWE-399Resource Management Errors
14% (44)CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer
13% (41)CWE-264Permissions, Privileges, and Access Controls
9% (29)CWE-20Improper Input Validation
8% (26)CWE-79Failure to Preserve Web Page Structure ('Cross-site Scripting')
Hide | Show 9 More...
%idName
6% (21)CWE-94Failure to Control Generation of Code ('Code Injection')
6% (20)CWE-200Information Exposure
4% (15)CWE-189Numeric Errors
2% (8)CWE-16Configuration
1% (5)CWE-287Improper Authentication
1% (5)CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path ...
1% (4)CWE-310Cryptographic Issues
0% (1)CWE-352Cross-Site Request Forgery (CSRF)
0% (1)CWE-59Improper Link Resolution Before File Access ('Link Following')

CAPEC : Common Attack Pattern Enumeration & Classificatio

idName
CAPEC-26Leveraging Race Conditions
CAPEC-29Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions
CAPEC-172Time and State Attacks

Oval Markup Language : Definitions

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
OvalIDName
oval:org.mitre.oval:def:10031The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and...
oval:org.mitre.oval:def:11691Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox...
oval:org.mitre.oval:def:10661Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla Fir...
oval:org.mitre.oval:def:9746Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before...
oval:org.mitre.oval:def:9626Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firef...
Hide | Show 20 More...
idName
oval:org.mitre.oval:def:10895Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before ...
oval:org.mitre.oval:def:11077Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey befor...
oval:org.mitre.oval:def:10502Integer underflow in the SSLv2 support in Mozilla Network Security Services (...
oval:org.mitre.oval:def:10012Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox ...
oval:org.mitre.oval:def:8757GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x be...
oval:org.mitre.oval:def:9730Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0....
oval:org.mitre.oval:def:10164Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before ...
oval:org.mitre.oval:def:10086The child frames in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, a...
oval:org.mitre.oval:def:11665Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly imp...
oval:org.mitre.oval:def:10759Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1...
oval:org.mitre.oval:def:10066Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5.x befor...
oval:org.mitre.oval:def:10711Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x b...
oval:org.mitre.oval:def:11208The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x b...
oval:org.mitre.oval:def:9547Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1...
oval:org.mitre.oval:def:11433Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1...
oval:org.mitre.oval:def:11122Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to repl...
oval:org.mitre.oval:def:10108Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox...
oval:org.mitre.oval:def:11066Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Fire...
oval:org.mitre.oval:def:11749Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 al...
oval:org.mitre.oval:def:10009Mozilla Firefox before 2.0.0.5 allows remote attackers to execute arbitrary c...

Open Source Vulnerability Database (OSVDB)

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
idDescription
77955Mozilla Multiple Product for Mac DOM Frame Deletion NULL Dereference Remote C...
76954Mozilla Multiple Product WebGL GPU Memory Random Image Disclosure
76952Mozilla Multiple Product Firebug JavaScript File Profiling Remote Memory Corr...
76950Mozilla Multiple Product Unchecked Allocation Failure Remote Memory Corruption
76949Mozilla Multiple Product SVG Non-SVG Link Remote Memory Corruption
Hide | Show 20 More...
idDescription
76948Mozilla Multiple Product Shift-JIS XSS
76947Mozilla Multiple Product JSSubScriptLoader loadSubScript Method XPCNativeWrap...
75841Mozilla Multiple Product Enter Key Download Dialog Verification Bypass
75840Mozilla Multiple Product PLUGINSPAGE Enter Key Addon Installation Verificatio...
74587Mozilla Multiple Products Tab Element Dropping Weakness Remote Code Execution
74586Mozilla Multiple Products RegExp.input Property Same Origin Policy Bypass Inf...
74585Mozilla Multiple Products Multiple Unspecified Memory Corruption (2011-2982)
74584Mozilla Multiple Products Event-Management Same Origin Policy Bypass Remote C...
74583Mozilla Multiple Products ThinkPadSensor::Startup() Function Path Subversion ...
74582Mozilla Multiple Products .appendChild() Function DOM Object Handling Remote ...
74581Mozilla Multiple Products SVGTextElement.getCharNumAtPosition() Function SVG ...
74448Mozilla Firefox HTTPS Session HTTP Set-Cookie Header HSTS includeSubDomains W...
74319Mozilla Multiple Products netwerk/cookie/nsCookieService.cpp nsCookieService:...
73193Mozilla Multiple Products Non-whitelisted Site Install Dialog Triggering Weak...
73189Mozilla Multiple Products WebGL Texture Image Rendering Cross-domain Image Da...
73188Mozilla Multiple Products Trailing Dot Cookie Cross-domain Information Disclo...
73187Mozilla Multiple Products nsXULCommandDispatcher.cpp Use-after-free Remote Co...
73186Mozilla Multiple Products nsSVGPointList::AppendElement() Use-after-free Remo...
73185Mozilla Multiple Products nsSVGPathSegList::ReplaceItem() Use-after-free Remo...
73184Mozilla Multiple Products Array.reduceRight() Method Overflow

Milw0rm Exploits

idDescription
2009-07-15Multiple Web Browsers Denial of Service Exploit (1 bug to rule them all)
2009-03-25Mozilla Firefox XSL Parsing Remote Memory Corruption PoC 0day

ExploitDB Exploits

idDescription
18531Mozilla Firefox Firefox 4.0.1 Array.reduceRight() Exploit
17974Mozilla Firefox Array.reduceRight() Integer Overflow Exploit
10544Mozilla Firefox Location Bar Spoofing Vulnerability
9663Mozilla Firefox 2.0.0.16 UTF-8 URL Remote Buffer Overflow Exploit
3340Mozilla Firefox <= 2.0.0.1 (location.hostname) Cross-Domain Vulnerability

Metasploit Exploits

idDescription
2011-06-21Mozilla Firefox Array.reduceRight() Integer Overflow
2011-05-10Mozilla Firefox 3.6.16 mChannel Use-After-Free Vulnerability
2011-05-10Mozilla Firefox 3.6.16 mChannel Use-After-Free
2011-02-02Mozilla Firefox "nsTreeRange" Dangling Pointer Vulnerability
2011-12-06Firefox 8/9 AttributeChildRemoved() Use-After-Free