Mozilla Seamonkey vulnerabilities
694 known vulnerabilities affecting mozilla/seamonkey.
Total CVEs
694
CISA KEV
1
actively exploited
Public exploits
42
Exploited in wild
6
Severity breakdown
CRITICAL327HIGH76MEDIUM277LOW14
Vulnerabilities
Page 20 of 35
CVE-2014-1592P3MEDIUMCVSS 6.8≤ 2.302014-12-11
CVE-2014-1592 [MEDIUM] CVE-2014-1592: Use-after-free vulnerability in the nsHtml5TreeOperation function in xul.dll in Mozilla Firefox befo
Use-after-free vulnerability in the nsHtml5TreeOperation function in xul.dll in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to execute arbitrary code by adding a second root element to an HTML5 document during parsing.
nvd
CVE-2010-3773P4MEDIUMCVSS 6.8≤ 2.0.10v1.0+42 more2010-12-10
CVE-2010-3773 [MEDIUM] CVE-2010-3773: Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, when the XMLHttp
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response. NOTE: this vulne
nvd
CVE-2006-1727P4HIGHCVSS 7.6fixed in 1.0.12006-04-14
CVE-2006-1727 [HIGH] CVE-2006-1727: Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to gain chrome privileges via multiple attack vectors related to the use of XBL scripts with "Print Preview".
nvd
CVE-2006-3805P3HIGHCVSS 7.5v1.0v1.0.1+1 more2006-07-27
CVE-2006-3805 [HIGH] CVE-2006-3805: The Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey b
The Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving garbage collection that causes deletion of a temporary object that is still being used.
nvd
CVE-2006-3807P3HIGHCVSS 7.5v1.0v1.0.1+1 more2006-07-27
CVE-2006-3807 [HIGH] CVE-2006-3807: Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote
Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code via script that changes the standard Object() constructor to return a reference to a privileged object and calling "named JavaScript functions" that use the constructor.
nvd
CVE-2006-1734P3MEDIUMCVSS 6.8≤ 1.0v1.02006-04-14
CVE-2006-1734 [MEDIUM] CVE-2006-1734: Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13,
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using the Object.watch method to access the "clone parent" internal function.
nvd
CVE-2008-5018P4CRITICALCVSS 10.0≥ 1.0, < 1.1.132008-11-13
CVE-2008-5018 [CRITICAL] CWE-399 CVE-2008-5018: The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird
The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.
nvd
CVE-2012-0459P4HIGHCVSS 7.5≤ 2.7v1.0+59 more2012-03-14
CVE-2012-0459 [HIGH] CWE-264 CVE-2012-0459: The Cascading Style Sheets (CSS) implementation in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.
The Cascading Style Sheets (CSS) implementation in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via dynamic modification of a keyframe
nvd
CVE-2011-3661P4HIGHCVSS 7.5≤ 2.5v1.0+52 more2011-12-21
CVE-2011-3661 [HIGH] CWE-399 CVE-2011-3661: YARR, as used in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before
YARR, as used in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted JavaScript.
nvd
CVE-2012-0462P4HIGHCVSS 7.5≤ 2.7v1.0+59 more2012-03-14
CVE-2012-0462 [HIGH] CVE-2012-0462: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 10.0, Fire
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vec
nvd
CVE-2006-1733P3MEDIUMCVSS 6.8≤ 1.0v1.02006-04-14
CVE-2006-1733 [MEDIUM] CWE-264 CVE-2006-1733: Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13,
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL bindings, which allows remote attackers to execute arbitrary code via the (1) valueOf.call or (2) valueOf.apply methods of an XBL binding, or (3) "by inse
nvd
CVE-2009-3979P4CRITICALCVSS 9.3≤ 2.0v1.0+34 more2009-12-17
CVE-2009-3979 [CRITICAL] CVE-2009-3979: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.16 and 3.5.
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2009-3982P4CRITICALCVSS 9.3≤ 2.0v1.0+34 more2009-12-17
CVE-2009-3982 [CRITICAL] CVE-2009-3982: Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.6,
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2009-3980P4CRITICALCVSS 9.3≤ 2.0v1.0+34 more2009-12-17
CVE-2009-3980 [CRITICAL] CWE-399 CVE-2009-3980: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.6, Se
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2008-2803P3MEDIUMCVSS 6.8≤ 1.1.9v1.1+7 more2008-07-07
CVE-2008-2803 [MEDIUM] CWE-264 CVE-2008-2803: The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.
The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 does not apply XPCNativeWrappers to scripts loaded from (1) file: URIs, (2) data: URIs, or (3) certain non-canonical chrome: URIs, which allows remote attackers to execute arbitrary code via vectors involving
nvd
CVE-2010-3771P4MEDIUMCVSS 6.8≤ 2.0.10v1.0+42 more2010-12-10
CVE-2010-3771 [MEDIUM] CVE-2010-3771: Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properl
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle injection of an ISINDEX element into an about:blank page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to redirection to a chrome: URI.
nvd
CVE-2011-2993P4CRITICALCVSS 9.3v2.0v2.0.1+11 more2011-08-18
CVE-2011-2993 [CRITICAL] CVE-2011-2993: The implementation of digital signatures for JAR files in Mozilla Firefox 4.x through 5, SeaMonkey 2
The implementation of digital signatures for JAR files in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not prevent calls from unsigned JavaScript code to signed code, which allows remote attackers to bypass the Same Origin Policy and gain privileges via a crafted web site, a different vulnerability than CVE-2008-
nvd
CVE-2008-5017P4CRITICALCVSS 10.0≥ 1.0, < 1.1.132008-11-13
CVE-2008-5017 [CRITICAL] CWE-189 CVE-2008-5017: Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4,
Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors.
nvd
CVE-2012-0463P4HIGHCVSS 7.5v1.0v1.0.1+60 more2012-03-14
CVE-2012-0463 [HIGH] CWE-20 CVE-2012-0463: The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 1
The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 does not check the validity of an instance after event dispatching, which allows remote attackers to cause a d
nvd
CVE-2007-5959P4CRITICALCVSS 9.3v1.0v1.0.1+13 more2007-11-26
CVE-2007-5959 [CRITICAL] CVE-2007-5959: Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 a
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger memory corruption.
nvd