Mozilla Seamonkey vulnerabilities
694 known vulnerabilities affecting mozilla/seamonkey.
Total CVEs
694
CISA KEV
1
actively exploited
Public exploits
42
Exploited in wild
1
Severity breakdown
CRITICAL327HIGH76MEDIUM277LOW14
Vulnerabilities
Page 20 of 35
CVE-2011-1187MEDIUMCVSS 5.0fixed in 2.92011-03-11
CVE-2011-1187 [MEDIUM] CWE-200 CVE-2011-1187: Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspe
Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."
nvd
CVE-2011-0055CRITICALCVSS 10.0≤ 2.0.11v1.0+43 more2011-03-02
CVE-2011-0055 [CRITICAL] CWE-399 CVE-2011-0055: Use-after-free vulnerability in the JSON.stringify method in js3250.dll in Mozilla Firefox before 3.
Use-after-free vulnerability in the JSON.stringify method in js3250.dll in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via unspecified vectors related to the js_HasOwnProperty function and garbage collection.
nvd
CVE-2011-0061CRITICALCVSS 9.3≤ 2.0.11v1.0+43 more2011-03-02
CVE-2011-0061 [CRITICAL] CWE-119 CVE-2011-0061: Buffer overflow in Mozilla Firefox 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey befo
Buffer overflow in Mozilla Firefox 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image.
nvd
CVE-2011-0053CRITICALCVSS 10.0≤ 2.0.11v1.0+43 more2011-03-02
CVE-2011-0053 [CRITICAL] CVE-2011-0053: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.17 and 3.6.
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2011-0057CRITICALCVSS 10.0≤ 2.0.11v1.0+43 more2011-03-02
CVE-2011-0057 [CRITICAL] CWE-399 CVE-2011-0057: Use-after-free vulnerability in the Web Workers implementation in Mozilla Firefox before 3.5.17 and
Use-after-free vulnerability in the Web Workers implementation in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to execute arbitrary code via vectors related to a JavaScript Worker and garbage collection.
nvd
CVE-2011-0058CRITICALCVSS 10.0≤ 2.0.11v1.0+43 more2011-03-02
CVE-2011-0058 [CRITICAL] CWE-119 CVE-2011-0058: Buffer overflow in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.1
Buffer overflow in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a long string that triggers construction of a long text run.
nvd
CVE-2011-0054CRITICALCVSS 10.0≤ 2.0.11v1.0+43 more2011-03-02
CVE-2011-0054 [CRITICAL] CWE-119 CVE-2011-0054: Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, a
Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via vectors involving non-local JavaScript variables, aka an "upvarMap" issue.
nvd
CVE-2011-0056CRITICALCVSS 10.0≤ 2.0.11v1.0+43 more2011-03-02
CVE-2011-0056 [CRITICAL] CWE-119 CVE-2011-0056: Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, a
Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via vectors involving exception timing and a large number of string values, aka an "atom map" issue.
nvd
CVE-2011-0051MEDIUMCVSS 6.8≤ 2.0.11v1.0+43 more2011-03-02
CVE-2011-0051 [MEDIUM] CWE-20 CVE-2011-0051: Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, does not properl
Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, does not properly handle certain recursive eval calls, which makes it easier for remote attackers to force a user to respond positively to a dialog question, as demonstrated by a question about granting privileges.
nvd
CVE-2011-0059MEDIUMCVSS 6.8≤ 2.0.11v1.0+43 more2011-03-02
CVE-2011-0059 [MEDIUM] CWE-352 CVE-2011-0059: Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.
Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated by a plugin and received a 307 redirect to a page on a different web site.
nvd
CVE-2010-3769CRITICALCVSS 9.3≤ 2.0.10v1.0+42 more2010-12-10
CVE-2010-3769 [CRITICAL] CWE-119 CVE-2010-3769: The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbi
The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that triggers a buffer over-read.
nvd
CVE-2010-3778CRITICALCVSS 9.3≤ 2.0.10v1.0+42 more2010-12-10
CVE-2010-3778 [CRITICAL] CWE-119 CVE-2010-3778: Unspecified vulnerability in Mozilla Firefox 3.5.x before 3.5.16, Thunderbird before 3.0.11, and Sea
Unspecified vulnerability in Mozilla Firefox 3.5.x before 3.5.16, Thunderbird before 3.0.11, and SeaMonkey before 2.0.11 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2010-3767CRITICALCVSS 9.3v1.0v1.0.1+42 more2010-12-10
CVE-2010-3767 [CRITICAL] CWE-189 CVE-2010-3767: Integer overflow in the NewIdArray function in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13
Integer overflow in the NewIdArray function in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via a JavaScript array with many elements.
nvd
CVE-2010-3776CRITICALCVSS 9.3≤ 2.0.10v1.0+42 more2010-12-10
CVE-2010-3776 [CRITICAL] CWE-119 CVE-2010-3776: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.16 and 3.6.
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2010-3775CRITICALCVSS 9.3≤ 2.0.10v1.0+42 more2010-12-10
CVE-2010-3775 [CRITICAL] CVE-2010-3775: Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properl
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle certain redirections involving data: URLs and Java LiveConnect scripts, which allows remote attackers to start processes, read arbitrary local files, and establish network connections via vectors involving a refresh value in the http-equiv attribute
nvd
CVE-2010-3766CRITICALCVSS 9.3v1.0v1.0.1+42 more2010-12-10
CVE-2010-3766 [CRITICAL] CWE-399 CVE-2010-3766: Use-after-free vulnerability in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey
Use-after-free vulnerability in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via vectors involving a change to an nsDOMAttribute node.
nvd
CVE-2010-3768CRITICALCVSS 9.3≤ 2.0.10v1.0+42 more2010-12-10
CVE-2010-3768 [CRITICAL] CWE-20 CVE-2010-3768: Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 do not properly validate downloadable fonts before use within an operating system's font implementation, which allows remote attackers to execute arbitrary code via vectors related to @font-face Cascading Style Sheets (
nvd
CVE-2010-3772CRITICALCVSS 9.3≤ 2.0.10v1.0+42 more2010-12-10
CVE-2010-3772 [CRITICAL] CWE-189 CVE-2010-3772: Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properl
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly calculate index values for certain child content in a XUL tree, which allows remote attackers to execute arbitrary code via vectors involving a DIV element within a treechildren element.
nvd
CVE-2010-3771MEDIUMCVSS 6.8≤ 2.0.10v1.0+42 more2010-12-10
CVE-2010-3771 [MEDIUM] CVE-2010-3771: Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properl
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle injection of an ISINDEX element into an about:blank page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to redirection to a chrome: URI.
nvd
CVE-2010-3770MEDIUMCVSS 4.3PoC≤ 2.0.10v1.0+42 more2010-12-10
CVE-2010-3770 [MEDIUM] CWE-79 CVE-2010-3770: Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox befor
Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allow remote attackers to inject arbitrary web script or HTML via (1) x-mac-arabic, (2) x-mac-farsi, or (3) x-mac-hebrew characters that may be converted to angle brackets during rendering.
nvd