Mozilla Seamonkey vulnerabilities
694 known vulnerabilities affecting mozilla/seamonkey.
Total CVEs
694
CISA KEV
1
actively exploited
Public exploits
42
Exploited in wild
6
Severity breakdown
CRITICAL327HIGH76MEDIUM277LOW14
Vulnerabilities
Page 25 of 35
CVE-2006-6498P4MEDIUMCVSS 6.8v1.0v1.0.1+5 more2006-12-20
CVE-2006-6498 [MEDIUM] CVE-2006-6498: Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla Firefox 2.x before 2.0.0.1
Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, SeaMonkey before 1.0.7, and Mozilla 1.7 and probably earlier on Solaris, allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown impact
nvd
CVE-2013-0759P4MEDIUMCVSS 5.0fixed in 2.152013-01-13
CVE-2013-0759 [MEDIUM] CWE-287 CVE-2013-0759: Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird bef
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to spoof the address bar via vectors involving authentication information in the userinfo field of a URL, in conjunction with a 204
nvd
CVE-2011-0067P4MEDIUMCVSS 5.0≤ 2.0.13v1.0+45 more2011-05-07
CVE-2011-0067 [MEDIUM] CWE-20 CVE-2011-0067: Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properl
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly implement autocompletion for forms, which allows remote attackers to read form history entries via a Java applet that spoofs interaction with the autocomplete controls.
nvd
CVE-2011-3062P4MEDIUMCVSS 6.8fixed in 2.92012-03-30
CVE-2011-3062 [MEDIUM] CWE-682 CVE-2011-3062: Off-by-one error in the OpenType Sanitizer in Google Chrome before 18.0.1025.142 allows remote attac
Off-by-one error in the OpenType Sanitizer in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted OpenType file.
nvd
CVE-2012-1942P4HIGHCVSS 7.2v2.92012-06-05
CVE-2012-1942 [HIGH] CWE-264 CVE-2012-1942: The Mozilla Updater and Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMo
The Mozilla Updater and Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allow local users to gain privileges by loading a DLL file in a privileged context.
nvd
CVE-2011-0059P4MEDIUMCVSS 6.8≤ 2.0.11v1.0+43 more2011-03-02
CVE-2011-0059 [MEDIUM] CWE-352 CVE-2011-0059: Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.
Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated by a plugin and received a 307 redirect to a page on a different web site.
nvd
CVE-2007-0779P4MEDIUMCVSS 6.4v1.0v1.0.1+7 more2007-02-26
CVE-2007-0779 [MEDIUM] CVE-2007-0779: GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMo
GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 allows remote attackers to spoof certain user interface elements, such as the host name or security indicators, via the CSS3 hotspot property with a large, transparent, custom cursor.
nvd
CVE-2008-5507P4MEDIUMCVSS 6.0≥ 1.0, < 1.1.142008-12-17
CVE-2008-5507 [MEDIUM] CWE-200 CVE-2008-5507: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMo
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScri
nvd
CVE-2006-0296P4MEDIUMCVSS 5.0v1.02006-02-02
CVE-2006-0296 [MEDIUM] CVE-2006-0296: The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does n
The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.
nvd
CVE-2012-3972P4MEDIUMCVSS 5.0fixed in 2.122012-08-29
CVE-2012-3972 [MEDIUM] CWE-200 CVE-2012-3972: The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox E
The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based buffer over-read.
nvd
CVE-2010-0163P4MEDIUMCVSS 4.3≤ 1.1.18v1.0+27 more2010-03-23
CVE-2010-0163 [MEDIUM] CVE-2010-0163: Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process e-mail attachments with a pa
Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process e-mail attachments with a parser that performs casts and line termination incorrectly, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted message, related to message indexing.
nvd
CVE-2006-2781P4MEDIUMCVSS 6.4≤ 1.0.12006-06-02
CVE-2006-2781 [MEDIUM] CWE-119 CVE-2006-2781: Double free vulnerability in nsVCard.cpp in Mozilla Thunderbird before 1.5.0.4 and SeaMonkey before
Double free vulnerability in nsVCard.cpp in Mozilla Thunderbird before 1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a VCard that contains invalid base64 characters.
nvd
CVE-2012-4205P4MEDIUMCVSS 6.8fixed in 2.142012-11-21
CVE-2012-4205 [MEDIUM] CWE-352 CVE-2012-4205: Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system pr
Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XMLHttpRequest objects created in sandboxes, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks or obtain sensitive information by leveraging a sandboxed add-on.
nvd
CVE-2006-5748P4MEDIUMCVSS 5.0v1.0v1.0.1+3 more2006-11-08
CVE-2006-5748 [MEDIUM] CVE-2006-5748: Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 1.5.0.8, Thu
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger memory corruption.
nvd
CVE-2014-1530P4MEDIUMCVSS 6.1fixed in 2.262014-04-30
CVE-2014-1530 [MEDIUM] CWE-79 CVE-2014-1530: The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbir
The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-site scripting (XSS) attacks, via a crafted web site that performs history navigation.
nvd
CVE-2006-0297P4MEDIUMCVSS 5.1v1.02006-02-02
CVE-2006-0297 [MEDIUM] CVE-2006-0297: Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail,
Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.
nvd
CVE-2010-1125P4MEDIUMCVSS 5.8≤ 2.0.4v1.0+35 more2010-03-26
CVE-2010-1125 [MEDIUM] CWE-200 CVE-2010-1125: The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMo
The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls to the focus method.
nvd
CVE-2009-0652P4MEDIUMCVSS 5.8≤ 1.1.14v1.0+22 more2009-02-20
CVE-2009-0652 [MEDIUM] CVE-2009-0652: The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions befor
The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters
nvd
CVE-2006-3804P4MEDIUMCVSS 5.0v1.0v1.0.1+1 more2006-07-27
CVE-2006-3804 [MEDIUM] CVE-2006-3804: Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey before 1.0.3 allows r
Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) via a VCard attachment with a malformed base64 field, which copies more data than expected due to an integer underflow.
nvd
CVE-2012-0441P4MEDIUMCVSS 5.0≤ 2.9v1.0+63 more2012-06-05
CVE-2012-0441 [MEDIUM] CWE-119 CVE-2012-0441: The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4,
The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10, allows remote attackers to cause a denial of service (application crash) via a zero-length i
nvd