cbcvebase.

Mozilla Seamonkey vulnerabilities

694 known vulnerabilities affecting mozilla/seamonkey.

Total CVEs
694
CISA KEV
1
actively exploited
Public exploits
42
Exploited in wild
6
Severity breakdown
CRITICAL327HIGH76MEDIUM277LOW14

Vulnerabilities

Page 18 of 35
CVE-2015-0817P3MEDIUMCVSS 6.8≤ 2.33.02015-03-24
CVE-2015-0817 [MEDIUM] CWE-17 CVE-2015-0817: The asm.js implementation in Mozilla Firefox before 36.0.3, Firefox ESR 31.x before 31.5.2, and SeaM The asm.js implementation in Mozilla Firefox before 36.0.3, Firefox ESR 31.x before 31.5.2, and SeaMonkey before 2.33.1 does not properly determine the cases in which bounds checking may be safely skipped during JIT compilation and heap access, which allows remote attackers to read or write to unintended memory locations, and consequently execute arbit
nvd
CVE-2008-3837P3CRITICALCVSS 9.3fixed in 1.1.122008-09-24
CVE-2008-3837 [CRITICAL] CVE-2008-3837: Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assist Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.
nvd
CVE-2014-1594P3MEDIUMCVSS 6.8≤ 2.302014-12-11
CVE-2014-1594 [MEDIUM] CWE-20 CVE-2014-1594: Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey be Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 might allow remote attackers to execute arbitrary code by leveraging an incorrect cast from the BasicThebesLayer data type to the BasicContainerLayer data type.
nvd
CVE-2012-3991P3CRITICALCVSS 9.3fixed in 2.132012-10-10
CVE-2012-3991 [CRITICAL] CWE-264 CVE-2012-3991: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict JSAPI access to the GetProperty function, which allows remote attackers to bypass the Same Origin Policy and possibly have unspecified other impact via a crafted web site.
nvd
CVE-2013-0773P3CRITICALCVSS 9.3fixed in 2.162013-02-19
CVE-2013-0773 [CRITICAL] CVE-2013-0773: The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox bef The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent modifications to a prototype, which allows remote attackers to obtain sensitive information from chrome objects o
nvd
CVE-2006-6500P3MEDIUMCVSS 6.8fixed in 1.0.72006-12-20
CVE-2006-6500 [MEDIUM] CWE-119 CVE-2006-6500: Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by setting the CSS cursor to certain images that cause an incorrect size calculation when converting to a Windows
nvd
CVE-2014-1497P3HIGHCVSS 8.8fixed in 2.252014-03-19
CVE-2014-1497 [HIGH] CWE-125 CVE-2014-1497: The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x b The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process heap memory, cause a denial of service (out-of-bounds read and application crash), or possibly have unspecified other impac
nvd
CVE-2014-1589P3MEDIUMCVSS 6.8≤ 2.302014-12-11
CVE-2014-1589 [MEDIUM] CWE-284 CVE-2014-1589: Mozilla Firefox before 34.0 and SeaMonkey before 2.31 provide stylesheets with an incorrect primary Mozilla Firefox before 34.0 and SeaMonkey before 2.31 provide stylesheets with an incorrect primary namespace, which allows remote attackers to bypass intended access restrictions via an XBL binding.
nvd
CVE-2008-4061P3CRITICALCVSS 10.0fixed in 1.1.122008-09-24
CVE-2008-4061 [CRITICAL] CWE-189 CVE-2008-4061: Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Th Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via an mtd element with a large integer value in the rowspan attri
nvd
CVE-2008-4062P3CRITICALCVSS 10.0fixed in 1.1.122008-09-24
CVE-2008-4062 [CRITICAL] CWE-399 CVE-2008-4062: Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunde Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine and (1) misinterpretation
nvd
CVE-2009-0353P3CRITICALCVSS 10.0≤ 1.1.13v1.0+21 more2009-02-04
CVE-2009-0353 [CRITICAL] CWE-399 CVE-2009-0353: Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaM Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine.
nvd
CVE-2012-5836P3HIGHCVSS 7.5fixed in 2.142012-11-21
CVE-2012-5836 [HIGH] CWE-94 CVE-2012-5836: Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote attacke Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving the setting of Cascading Style Sheets (CSS) properties in conjunction with SVG text.
nvd
CVE-2006-3801P3HIGHCVSS 7.5v1.0v1.0.1+1 more2006-07-27
CVE-2006-3801 [HIGH] CVE-2006-3801: Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 does not properly clear a JavaScript r Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 does not properly clear a JavaScript reference to a frame or window, which leaves a pointer to a deleted object that allows remote attackers to execute arbitrary native code.
nvd
CVE-2011-2992P3CRITICALCVSS 10.0v2.0v2.0.1+11 more2011-08-18
CVE-2011-2992 [CRITICAL] CWE-119 CVE-2011-2992: The Ogg reader in the browser engine in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, Thu The Ogg reader in the browser engine in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, Thunderbird before 6, and possibly other products allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2008-2802P3HIGHCVSS 7.5≤ 1.1.9v1.1+7 more2008-07-07
CVE-2008-2802 [HIGH] CWE-264 CVE-2008-2802: Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to execute arbitrary code via an XUL document that includes a script from a chrome: URI that points to a fastload file, related to this file's "privilege level."
nvd
CVE-2010-0178P3HIGHCVSS 7.6≤ 2.0.3v1.0+33 more2010-04-05
CVE-2010-0178 [HIGH] CWE-94 CVE-2010-0178: Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0. Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mouse clicks as drag-and-drop actions, which allows remote attackers to execute arbitrary JavaScript with Chrome privileges by loading a chrome: URL and then loading a javascript: URL.
nvd
CVE-2010-1200P4CRITICALCVSS 9.3≤ 2.0.4v1.0+33 more2010-06-24
CVE-2010-1200 [CRITICAL] CVE-2010-1200: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.10 an Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2010-1202P3CRITICALCVSS 9.3≤ 2.0.4v1.0+33 more2010-06-24
CVE-2010-1202 [CRITICAL] CVE-2010-1202: Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.10 Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2013-0783P4CRITICALCVSS 9.3fixed in 2.162013-02-19
CVE-2013-0783 [CRITICAL] CVE-2013-0783: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2010-3173P3HIGHCVSS 7.5≤ 2.0.8v1.0+40 more2010-10-21
CVE-2010-3173 [HIGH] CWE-310 CVE-2010-3173: The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack
nvd