cbcvebase.

Mozilla Seamonkey vulnerabilities

694 known vulnerabilities affecting mozilla/seamonkey.

Total CVEs
694
CISA KEV
1
actively exploited
Public exploits
42
Exploited in wild
6
Severity breakdown
CRITICAL327HIGH76MEDIUM277LOW14

Vulnerabilities

Page 26 of 35
CVE-2013-1737P4MEDIUMCVSS 5.0≤ 2.20v2.0+35 more2013-09-18
CVE-2013-1737 [MEDIUM] CWE-264 CVE-2013-1737: Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ES Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expan
nvd
CVE-2012-1959P4MEDIUMCVSS 5.0≤ 2.10v1.0+48 more2012-07-18
CVE-2012-1959 [MEDIUM] CWE-264 CVE-2012-1959: Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thun Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not consider the presence of same-compartment security wrappers (SCSW) during the cross-compartment wrapping of objects, which allows remote attackers to bypass intended XBL access restriction
nvd
CVE-2008-1238P4MEDIUMCVSS 5.0≤ 1.1.82008-03-27
CVE-2008-1238 [MEDIUM] CWE-287 CVE-2008-1238: Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request
nvd
CVE-2011-2362P4MEDIUMCVSS 5.0v1.0v1.0.1+46 more2011-06-30
CVE-2011-2362 [MEDIUM] CWE-264 CVE-2011-2362: Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 do not distin Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 do not distinguish between cookies for two domain names that differ only in a trailing dot, which allows remote web servers to bypass the Same Origin Policy via Set-Cookie headers.
nvd
CVE-2007-5337P4MEDIUMCVSS 4.3≤ 1.1.42007-10-21
CVE-2007-5337 [MEDIUM] CWE-200 CVE-2007-5337: Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome- Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other fi
nvd
CVE-2007-1095P4MEDIUMCVSS 6.8≤ 1.1.4v1.0+13 more2007-02-26
CVE-2007-1095 [MEDIUM] CVE-2007-1095: Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnl Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site that is visited by a client.
nvd
CVE-2012-4184P4MEDIUMCVSS 4.3fixed in 2.132012-10-10
CVE-2012-4184 [MEDIUM] CWE-79 CVE-2012-4184: The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x befo The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not prevent access to properties of a prototype for a standard class, which allows remote attackers to execute arbitrary JavaScript code with chrome pr
nvd
CVE-2010-0161P4MEDIUMCVSS 4.3≤ 1.1.18v1.0+27 more2010-03-23
CVE-2010-0161 [MEDIUM] CWE-399 CVE-2010-0161: The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in Mozilla Thunderbird before 2.0. The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 on Windows Vista, Windows Server 2008 R2, and Windows 7 allows remote SMTP, IMAP, and POP servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via crafted
nvd
CVE-2014-8631P4MEDIUMCVSS 4.3≤ 2.302014-12-11
CVE-2014-8631 [MEDIUM] CWE-284 CVE-2014-8631: The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2 The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 supports native-interface passing, which allows remote attackers to bypass intended DOM object restrictions via a call to an unspecified method.
nvd
CVE-2011-3664P4MEDIUMCVSS 6.8≤ 2.5v1.0+52 more2011-12-21
CVE-2011-3664 [MEDIUM] CVE-2011-3664: Mozilla Firefox before 9.0, Thunderbird before 9.0, and SeaMonkey before 2.6 on Mac OS X do not prop Mozilla Firefox before 9.0, Thunderbird before 9.0, and SeaMonkey before 2.6 on Mac OS X do not properly handle certain DOM frame deletions by plugins, which allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) or possibly have unspecified other impact via a crafted web site.
nvd
CVE-2013-0772P4MEDIUMCVSS 5.8fixed in 2.162013-02-19
CVE-2013-0772 [MEDIUM] CWE-119 CVE-2013-0772: The RasterImage::DrawFrameTo function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and The RasterImage::DrawFrameTo function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) via a crafted GIF image.
nvd
CVE-2010-3400P4MEDIUMCVSS 5.8≤ 2.0.4v1.0+31 more2010-09-15
CVE-2010-3400 [MEDIUM] CVE-2010-3400: The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 a The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses the current time for seeding of a random number generator, which makes it easier for remote attackers to guess the seed value via a brute-force attack, a different vulnerability than CVE-2008-5913.
nvd
CVE-2014-1483P4MEDIUMCVSS 5.0fixed in 2.242014-02-06
CVE-2014-1483 [MEDIUM] CWE-1021 CVE-2014-1483: Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Orig Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.
nvd
CVE-2008-5510P4MEDIUMCVSS 5.0≥ 1.0, < 1.1.142008-12-17
CVE-2008-5510 [MEDIUM] CVE-2008-5510: The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2 The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.
nvd
CVE-2012-1960P4MEDIUMCVSS 5.0≤ 2.10v1.0+48 more2012-07-18
CVE-2012-1960 [MEDIUM] CWE-200 CVE-2012-1960: The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 4.x The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through 13.0, and SeaMonkey before 2.11 might allow remote attackers to obtain sensitive information from process memory via a crafted color profile that triggers an out-of-bounds read operation.
nvd
CVE-2011-1187P4MEDIUMCVSS 5.0fixed in 2.92011-03-11
CVE-2011-1187 [MEDIUM] CWE-200 CVE-2011-1187: Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspe Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."
nvd
CVE-2008-4069P4MEDIUMCVSS 5.0≤ 1.1.11v1.0+13 more2008-09-24
CVE-2008-4069 [MEDIUM] CWE-200 CVE-2008-4069: The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attacke The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted XBM image file.
nvd
CVE-2011-2986P4MEDIUMCVSS 5.0v1.0v1.0.1+44 more2011-08-18
CVE-2011-2986 [MEDIUM] CWE-200 CVE-2011-2986: Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other pr Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used on Windows, allows remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas.
nvd
CVE-2012-3986P4MEDIUMCVSS 4.3fixed in 2.132012-10-10
CVE-2012-3986 [MEDIUM] CWE-20 CVE-2012-3986: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils) methods, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code.
nvd
CVE-2010-3178P4MEDIUMCVSS 5.8≤ 2.0.8v1.0+40 more2010-10-21
CVE-2010-3178 [MEDIUM] CWE-264 CVE-2010-3178: Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1 Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 do not properly handle certain modal calls made by javascript: URLs in circumstances related to opening a new window and performing cross-domain navigation, which allows remote attackers to bypass the Same Origin Policy vi
nvd