Mozilla Seamonkey vulnerabilities
694 known vulnerabilities affecting mozilla/seamonkey.
Total CVEs
694
CISA KEV
1
actively exploited
Public exploits
42
Exploited in wild
6
Severity breakdown
CRITICAL327HIGH76MEDIUM277LOW14
Vulnerabilities
Page 32 of 35
CVE-2013-1709P4MEDIUMCVSS 4.3≤ 2.20v2.0+51 more2013-08-07
CVE-2013-1709 [MEDIUM] CWE-79 CVE-2013-1709: Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird
Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly handle the interaction between FRAME elements and history, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving spoofing a relative location in
nvd
CVE-2010-0182P4MEDIUMCVSS 4.3≤ 2.0.3v1.0+33 more2010-04-05
CVE-2010-0182 [MEDIUM] CWE-20 CVE-2010-0182: The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird b
The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content.
nvd
CVE-2012-1943P4MEDIUMCVSS 6.9v2.92012-06-05
CVE-2012-1943 [MEDIUM] CVE-2012-1943: Untrusted search path vulnerability in Updater.exe in the Windows Updater Service in Mozilla Firefox
Untrusted search path vulnerability in Updater.exe in the Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allows local users to gain privileges via a Trojan horse wsock32.dll file in an application directory.
nvd
CVE-2010-3181P4MEDIUMCVSS 6.9≤ 2.0.8v1.0+40 more2010-10-21
CVE-2010-3181 [MEDIUM] CVE-2010-3181: Untrusted search path vulnerability in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunde
Untrusted search path vulnerability in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory.
nvd
CVE-2009-3007P4MEDIUMCVSS 4.3v1.1.72009-08-28
CVE-2009-3007 [MEDIUM] CVE-2009-3007: Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to sp
Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.
nvd
CVE-2009-1304P4MEDIUMCVSS 5.0≤ 1.1.13v1.0+23 more2009-04-22
CVE-2009-1304 [MEDIUM] CWE-399 CVE-2009-1304: The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonke
The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving (1) js_FindPropertyHelper, related to the definitions of Math and Date; and (2) js_CheckRedeclaration.
nvd
CVE-2009-1303P4MEDIUMCVSS 5.0≤ 1.1.15v1.0+28 more2009-04-22
CVE-2009-1303 [MEDIUM] CWE-16 CVE-2009-1303: The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey befor
The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree.
nvd
CVE-2013-1708P4MEDIUMCVSS 4.3≤ 2.20v2.0+51 more2013-08-07
CVE-2013-1708 [MEDIUM] CVE-2013-1708: Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of se
Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (application crash) via a crafted WAV file that is not properly handled by the nsCString::CharAt function.
nvd
CVE-2008-1234P4MEDIUMCVSS 4.3≤ 1.1.82008-03-27
CVE-2008-1234 [MEDIUM] CWE-79 CVE-2008-1234: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to inject arbitrary web script or HTML via event handlers, aka "Universal XSS using event handlers."
nvd
CVE-2008-5913P4MEDIUMCVSS 4.9≤ 2.0.4v1.0+31 more2009-01-20
CVE-2008-5913 [MEDIUM] CVE-2008-5913: The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating t
nvd
CVE-2009-1835P4MEDIUMCVSS 4.3≤ 1.1.16v1.0+20 more2009-06-12
CVE-2009-1835 [MEDIUM] CWE-200 CVE-2009-1835: Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external do
Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assisted remote attackers to read arbitrary cookies via a crafted HTML document, as demonstrated by a URL with file://example.com/C:/ at the beginning.
nvd
CVE-2008-0415P4MEDIUMCVSS 4.3≤ 1.1.72008-02-08
CVE-2008-0415 [MEDIUM] CWE-79 CVE-2008-0415: Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remo
Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."
nvd
CVE-2010-1197P4MEDIUMCVSS 4.3≤ 2.0.4v1.0+33 more2010-06-24
CVE-2010-1197 [MEDIUM] CWE-79 CVE-2010-1197: Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not pro
Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not properly handle situations in which both "Content-Disposition: attachment" and "Content-Type: multipart" are present in HTTP headers, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an uploaded HTML document.
nvd
CVE-2008-0593P4MEDIUMCVSS 4.3≤ 1.1.17v1.0+20 more2008-02-09
CVE-2008-0593 [MEDIUM] CWE-200 CVE-2008-0593: Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify t
Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote attackers to bypass the Same Origin Policy and read sensitive information from the original URL, such as with Single-Signon systems.
nvd
CVE-2009-3010P4MEDIUMCVSS 4.3v1.1.172009-08-31
CVE-2009-3010 [MEDIUM] CWE-79 CVE-2009-3010: Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly block data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains JavaScript sequences i
nvd
CVE-2008-0416P4MEDIUMCVSS 4.3≤ 1.1.72008-02-12
CVE-2008-0416 [MEDIUM] CWE-79 CVE-2008-0416: Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allow remote attackers to inject arbitrary web script or HTML via certain character encodings, including (1) a backspace character that is treated as whitespace, (2) 0x80 with Shift_JIS encoding, and (3) "zero-l
nvd
CVE-2007-5960P4MEDIUMCVSS 4.3≤ 1.1.72007-11-26
CVE-2007-5960 [MEDIUM] CWE-22 CVE-2007-5960: Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or
Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal al
nvd
CVE-2012-4192P4MEDIUMCVSS 4.3v2.132012-10-12
CVE-2012-4192 [MEDIUM] CWE-264 CVE-2012-4192: Mozilla Firefox 16.0, Thunderbird 16.0, and SeaMonkey 2.13 allow remote attackers to bypass the Same
Mozilla Firefox 16.0, Thunderbird 16.0, and SeaMonkey 2.13 allow remote attackers to bypass the Same Origin Policy and read the properties of a Location object via a crafted web site, a related issue to CVE-2012-4193.
nvd
CVE-2006-4340P4MEDIUMCVSS 4.0≤ 1.0.42006-09-15
CVE-2006-4340 [MEDIUM] CWE-20 CVE-2006-4340: Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulner
nvd
CVE-2010-1206P4MEDIUMCVSS 4.3≤ 2.0.5v1.0+38 more2010-06-25
CVE-2010-1206 [MEDIUM] CWE-264 CVE-2010-1206: The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.
The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading, which allows (1) remote web servers to con
nvd