cbcvebase.

Mozilla Seamonkey vulnerabilities

694 known vulnerabilities affecting mozilla/seamonkey.

Total CVEs
694
CISA KEV
1
actively exploited
Public exploits
42
Exploited in wild
6
Severity breakdown
CRITICAL327HIGH76MEDIUM277LOW14

Vulnerabilities

Page 1 of 35
CVE-2010-3765P1CRITICALCVSS 9.8KEVPoCv2.0v2.0.1+8 more2010-10-28
CVE-2010-3765 [CRITICAL] CWE-119 CVE-2010-3765: Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3. Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the
nvd
CVE-2014-1510P1CRITICALCVSS 9.8ExploitedPoCfixed in 2.252014-03-19
CVE-2014-1510 [CRITICAL] CWE-269 CVE-2014-1510: The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment to trigger a window.open call.
nvd
CVE-2014-1511P1CRITICALCVSS 9.8ExploitedPoCfixed in 2.252014-03-19
CVE-2014-1511 [CRITICAL] CWE-269 CVE-2014-1511: Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey be Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors.
nvd
CVE-2006-3677P2HIGHCVSS 7.5ExploitedPoCv1.0v1.0.1+1 more2006-07-27
CVE-2006-3677 [HIGH] CWE-16 CVE-2006-3677: Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arb Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash that leads to code execution.
nvd
CVE-2014-8636P2HIGHCVSS 7.5ExploitedPoC≤ 2.312015-01-14
CVE-2014-8636 [HIGH] CWE-94 CVE-2014-8636: The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not pro The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that has a named getter, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via unspecified vectors.
nvd
CVE-2013-1710P2CRITICALCVSS 10.0ExploitedPoC≤ 2.20v2.0+51 more2013-08-07
CVE-2013-1710 [CRITICAL] CWE-20 CVE-2013-1710: The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0 The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allows remote attackers to execute arbitrary JavaScript code or conduct cross-site scripting (XSS) attacks via vectors related to Certificate Request Message F
nvd
CVE-2013-0758P2CRITICALCVSS 9.3PoCfixed in 2.152013-01-13
CVE-2013-0758 [CRITICAL] CWE-94 CVE-2013-0758: Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird bef Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging improper interaction between plugin objects and SVG eleme
nvd
CVE-2011-2371P2CRITICALCVSS 10.0PoCv1.0v1.0.1+46 more2011-06-30
CVE-2011-2371 [CRITICAL] CWE-189 CVE-2011-2371: Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4. Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via vectors involving a long JavaScript Array object.
nvd
CVE-2011-0065P2CRITICALCVSS 10.0PoC≤ 2.0.13v1.0+45 more2011-05-07
CVE-2011-0065 [CRITICAL] CWE-399 CVE-2011-0065: Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mChannel.
nvd
CVE-2010-1205P2CRITICALCVSS 9.8PoCfixed in 2.0.62010-06-30
CVE-2010-1205 [CRITICAL] CWE-120 CVE-2010-1205: Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
nvd
CVE-2011-0073P2CRITICALCVSS 10.0PoC≤ 2.0.13v1.0+45 more2011-05-07
CVE-2011-0073 [CRITICAL] CWE-20 CVE-2011-0073: Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properl Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."
nvd
CVE-2013-0753P2CRITICALCVSS 9.3PoCfixed in 2.152013-01-13
CVE-2013-0753 [CRITICAL] CWE-416 CVE-2013-0753: Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code v
nvd
CVE-2013-0757P2CRITICALCVSS 9.3PoCfixed in 2.152013-01-13
CVE-2013-0757 [CRITICAL] CWE-20 CVE-2013-0757: The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x befo The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not prevent modifications to the prototype of an object, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges
nvd
CVE-2013-2566P2MEDIUMCVSS 5.9PoCfixed in 2.22.12013-03-15
CVE-2013-2566 [MEDIUM] CWE-326 CVE-2013-2566: The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.
nvd
CVE-2011-3659P2CRITICALCVSS 9.3PoCfixed in 2.72012-02-01
CVE-2011-3659 [CRITICAL] CWE-416 CVE-2011-3659: Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird befor Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes.
nvd
CVE-2008-0016P2CRITICALCVSS 10.0PoC≤ 1.1.11v1.0+13 more2008-09-24
CVE-2008-0016 [CRITICAL] CWE-119 CVE-2008-0016: Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.
nvd
CVE-2012-3993P2CRITICALCVSS 9.3PoC≤ 2.13v2.0+37 more2012-10-10
CVE-2012-3993 [CRITICAL] CWE-269 CVE-2012-3993: The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x befo The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not properly interact with failures of InstallTrigger methods, which allows remote attackers to execute arbitrary JavaScript code with chrome privil
nvd
CVE-2011-3658P3HIGHCVSS 7.5PoCv2.52011-12-21
CVE-2011-3658 [HIGH] CWE-399 CVE-2011-3658: The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via vectors involving removal of SVG elements.
nvd
CVE-2015-4000P3LOWCVSS 3.7PoCv2.352015-05-21
CVE-2015-4000 [LOW] CWE-310 CVE-2015-4000: The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, a
nvd
CVE-2009-3373P3CRITICALCVSS 10.0PoC≤ 1.5.0.10v1.0+29 more2009-10-29
CVE-2009-3373 [CRITICAL] CWE-119 CVE-2009-3373: Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
1 / 35Next →
Mozilla Seamonkey vulnerabilities | cvebase