cbcvebase.

Mozilla Seamonkey vulnerabilities

694 known vulnerabilities affecting mozilla/seamonkey.

Total CVEs
694
CISA KEV
1
actively exploited
Public exploits
42
Exploited in wild
6
Severity breakdown
CRITICAL327HIGH76MEDIUM277LOW14

Vulnerabilities

Page 27 of 35
CVE-2012-0456P4MEDIUMCVSS 5.0v1.0v1.0.1+60 more2012-03-14
CVE-2012-0456 [MEDIUM] CWE-200 CVE-2012-0456: The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10 The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 might allow remote attackers to obtain sensitive information from process memory via vectors that trigger an out-of-bounds rea
nvd
CVE-2008-2805P4MEDIUMCVSS 5.0≤ 1.1.9v1.1+7 more2008-07-07
CVE-2008-2805 [MEDIUM] CWE-20 CVE-2008-2805: Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to force the uplo Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to force the upload of arbitrary local files from a client computer via vectors involving originalTarget and DOM Range.
nvd
CVE-2014-8637P4MEDIUMCVSS 5.0≤ 2.312015-01-14
CVE-2014-8637 [MEDIUM] CWE-200 CVE-2014-8637: Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP imag Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers the rendering of malformed BMP data within a CANVAS element.
nvd
CVE-2012-0447P4MEDIUMCVSS 5.0≤ 2.7v1.0+57 more2012-02-01
CVE-2012-0447 [MEDIUM] CWE-200 CVE-2012-0447: Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not proper Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon images, which allows remote attackers to obtain potentially sensitive information by reading a PNG image that was created through conversion from an ICO image.
nvd
CVE-2006-3810P4MEDIUMCVSS 6.8v1.0v1.0.1+1 more2006-07-27
CVE-2006-3810 [MEDIUM] CVE-2006-3810: Cross-site scripting (XSS) vulnerability in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1 Cross-site scripting (XSS) vulnerability in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the XPCNativeWrapper(window).Function construct.
nvd
CVE-2013-6672P4MEDIUMCVSS 4.3fixed in 2.232013-12-11
CVE-2013-6672 [MEDIUM] CWE-200 CVE-2013-6672: Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers to read clipboard data by leveraging certain middle-click paste operations.
nvd
CVE-2007-3511P4MEDIUMCVSS 4.3≤ 1.1.4v1.0+14 more2007-07-03
CVE-2007-3511 [MEDIUM] CVE-2007-3511: The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions b The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.
nvd
CVE-2013-5614P4MEDIUMCVSS 4.3fixed in 2.232013-12-11
CVE-2013-5614 [MEDIUM] CWE-1021 CVE-2013-5614: Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended sandbox restrictions via a crafted web site.
nvd
CVE-2006-1729P4MEDIUMCVSS 4.3fixed in 1.0.12006-04-14
CVE-2006-1729 [MEDIUM] CWE-20 CVE-2006-1729: Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonke Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.
nvd
CVE-2012-3975P4MEDIUMCVSS 4.3≤ 2.11v2.0+31 more2012-08-29
CVE-2012-3975 [MEDIUM] CWE-200 CVE-2012-3975: The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey befor The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 loads subresources during parsing of text/html data within an extension, which allows remote attackers to obtain sensitive information by providing crafted data to privileged extension code.
nvd
CVE-2012-1963P4MEDIUMCVSS 4.3≤ 2.10v1.0+48 more2012-07-18
CVE-2012-1963 [MEDIUM] CWE-264 CVE-2012-1963: The Content Security Policy (CSP) functionality in Mozilla Firefox 4.x through 13.0, Firefox ESR 10. The Content Security Policy (CSP) functionality in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly restrict the strings placed into the blocked-uri parameter of a violation report, which allows remote web servers to capture O
nvd
CVE-2014-8632P4MEDIUMCVSS 4.3≤ 2.302014-12-11
CVE-2014-8632 [MEDIUM] CWE-284 CVE-2014-8632: The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does no The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote attackers to bypass intended DOM object restrictions by leveraging property availability after XrayWrapper removal.
nvd
CVE-2010-3182P4MEDIUMCVSS 6.9≤ 2.0.8v1.0+40 more2010-10-21
CVE-2010-3182 [MEDIUM] CVE-2010-3182: A certain application-launch script in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunde A certain application-launch script in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Linux places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
nvd
CVE-2007-0778P4MEDIUMCVSS 5.4fixed in 1.0.82007-02-26
CVE-2007-0778 [MEDIUM] CWE-200 CVE-2007-0778: The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey befo The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache.
nvd
CVE-2006-1742P4MEDIUMCVSS 5.0≤ 1.0v1.02006-04-14
CVE-2006-1742 [MEDIUM] CVE-2006-1742: The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozi The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly handle temporary variables that are not garbage collected, which might allow remote attackers to trigger operations on freed memory and cause memory corruption.
nvd
CVE-2008-5501P4MEDIUMCVSS 5.0≥ 1.0, < 1.1.142008-12-17
CVE-2008-5501 [MEDIUM] CVE-2008-5501: The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonke The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service via vectors that trigger an assertion failure.
nvd
CVE-2013-0794P4MEDIUMCVSS 5.8≤ 2.17v2.0+47 more2013-04-03
CVE-2013-0794 [MEDIUM] CVE-2013-0794: Mozilla Firefox before 20.0 and SeaMonkey before 2.17 do not prevent origin spoofing of tab-modal di Mozilla Firefox before 20.0 and SeaMonkey before 2.17 do not prevent origin spoofing of tab-modal dialogs, which allows remote attackers to conduct phishing attacks via a crafted web site.
nvd
CVE-2006-6503P4MEDIUMCVSS 6.8fixed in 1.0.72006-12-20
CVE-2006-6503 [MEDIUM] CWE-254 CVE-2006-6503: Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: URI.
nvd
CVE-2014-8640P4MEDIUMCVSS 5.0≤ 2.312015-01-14
CVE-2014-8640 [MEDIUM] CWE-362 CVE-2014-8640: The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the Web Audio API implementati The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the Web Audio API implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly restrict timeline operations, which allows remote attackers to cause a denial of service (uninitialized-memory read and application crash) via crafted API calls.
nvd
CVE-2009-3988P4MEDIUMCVSS 5.0v2.02010-02-22
CVE-2009-3988 [MEDIUM] CWE-264 CVE-2009-3988: Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not pro Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.
nvd
Mozilla Seamonkey vulnerabilities | cvebase