CVE-2009-3385
published 2010-03-23CVE-2009-3385: The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted remote…
PriorityP427high7.1CVSS 2.0
AVNACMAuNCCINAN
EPSS
2.77%
84.7th percentile
The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted remote attackers to obtain sensitive information via crafted content in an IFRAME element in an HTML e-mail message, as demonstrated by a Flash object that sends arbitrary local files during a reply or forward operation.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | seamonkey | <= 1.1.18 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:C/I:N/A:N
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla SeaMonkey up to 1.1.18 access control (Nessus ID 42296 / ID 155780)
vuldb·2026-05-03·CVSS 7.1
CVE-2009-3385 [HIGH] Mozilla SeaMonkey up to 1.1.18 access control (Nessus ID 42296 / ID 155780)
A vulnerability, which was classified as problematic, was found in Mozilla SeaMonkey. The affected element is an unknown function. The manipulation results in improper access controls.
This vulnerability was named CVE-2009-3385. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
GHSA
GHSA-wj9q-fjc4-6whp: The mail component in Mozilla SeaMonkey before 1
ghsa_unreviewed·2022-05-02
CVE-2009-3385 [HIGH] GHSA-wj9q-fjc4-6whp: The mail component in Mozilla SeaMonkey before 1
The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted remote attackers to obtain sensitive information via crafted content in an IFRAME element in an HTML e-mail message, as demonstrated by a Flash object that sends arbitrary local files during a reply or forward operation.
Red Hat
SeaMonkey scriptable plugin execution in mail (mfsa2010-06)
vendor_redhat·2009-10-27·CVSS 7.1
CVE-2009-3385 [HIGH] SeaMonkey scriptable plugin execution in mail (mfsa2010-06)
SeaMonkey scriptable plugin execution in mail (mfsa2010-06)
The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted remote attackers to obtain sensitive information via crafted content in an IFRAME element in an HTML e-mail message, as demonstrated by a Flash object that sends arbitrary local files during a reply or forward operation.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/39001http://www.mozilla.org/security/announce/2010/mfsa2010-06.htmlhttp://www.securityfocus.com/bid/38830http://www.vupen.com/english/advisories/2010/0648https://bugzilla.mozilla.org/show_bug.cgi?id=371976https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10271http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/39001http://www.mozilla.org/security/announce/2010/mfsa2010-06.htmlhttp://www.securityfocus.com/bid/38830http://www.vupen.com/english/advisories/2010/0648https://bugzilla.mozilla.org/show_bug.cgi?id=371976https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10271
2010-03-23
Published