cbcvebase.

Mozilla Seamonkey vulnerabilities

694 known vulnerabilities affecting mozilla/seamonkey.

Total CVEs
694
CISA KEV
1
actively exploited
Public exploits
42
Exploited in wild
6
Severity breakdown
CRITICAL327HIGH76MEDIUM277LOW14

Vulnerabilities

Page 34 of 35
CVE-2010-2754P4MEDIUMCVSS 5.0≤ 2.0.5v1.0+38 more2010-07-30
CVE-2010-2754 [MEDIUM] CWE-200 CVE-2010-2754: dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderb dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not properly suppress a script's URL in certain circumstances involving a redirect and an error message, which allows remote attackers to obtain sensitive information about s
nvd
CVE-2007-5947P4MEDIUMCVSS 4.3≤ 1.1.6v1.1.1+4 more2007-11-14
CVE-2007-5947 [MEDIUM] CWE-79 CVE-2007-5947: The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.
nvd
CVE-2007-2871P4MEDIUMCVSS 4.3v1.0.9v1.1.22007-06-01
CVE-2007-2871 [MEDIUM] CVE-2007-2871: Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to spoof or hide the browser chrome, such as the location bar, by placing XUL popups outside of the browser's content pane. NOTE: this issue can be leveraged for phishing and other attacks.
nvd
CVE-2006-4568P4MEDIUMCVSS 4.3≤ 1.0.42006-09-15
CVE-2006-4568 [MEDIUM] CWE-79 CVE-2006-4568: Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the secu Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.
nvd
CVE-2011-3663P4MEDIUMCVSS 4.3≤ 2.5v1.0+56 more2011-12-21
CVE-2011-3663 [MEDIUM] CWE-200 CVE-2011-3663: Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to capture keystrokes entered on a web page, even when JavaScript is disabled, by using SVG animation accessKey events within that web page.
nvd
CVE-2008-2800P4MEDIUMCVSS 4.3≤ 1.1.9v1.1+7 more2008-07-07
CVE-2008-2800 [MEDIUM] CWE-79 CVE-2008-2800: Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Sam Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors involving (1) an event handler attached to an outer window, (2) a SCRIPT element in an unloaded document, or (3) the onreadystatechange handler in conjunction with an XMLHttpReque
nvd
CVE-2014-1590P4MEDIUMCVSS 4.3≤ 2.302014-12-11
CVE-2014-1590 [MEDIUM] CWE-20 CVE-2014-1590: The XMLHttpRequest.prototype.send method in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31. The XMLHttpRequest.prototype.send method in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to cause a denial of service (application crash) via a crafted JavaScript object.
nvd
CVE-2008-6961P4MEDIUMCVSS 4.3≤ 1.1.12v1.0+14 more2009-08-13
CVE-2008-6961 [MEDIUM] CWE-200 CVE-2008-6961: mailnews in Mozilla Thunderbird before 2.0.0.18 and SeaMonkey before 1.1.13, when JavaScript is enab mailnews in Mozilla Thunderbird before 2.0.0.18 and SeaMonkey before 1.1.13, when JavaScript is enabled in mail, allows remote attackers to obtain sensitive information about the recipient, or comments in forwarded mail, via script that reads the (1) .documentURI or (2) .textContent DOM properties.
nvd
CVE-2008-2808P4MEDIUMCVSS 4.3v1.1v1.1.1+8 more2008-07-07
CVE-2008-2808 [MEDIUM] CWE-79 CVE-2008-2808: Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// U Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// URLs in directory listings, which allows remote attackers to conduct cross-site scripting (XSS) attacks or have unspecified other impact via a crafted filename.
nvd
CVE-2013-0774P4MEDIUMCVSS 4.3fixed in 2.162013-02-19
CVE-2013-0774 [MEDIUM] CVE-2013-0774: Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent JavaScript workers from reading the browser-profile directory name, which has unspecified impact and remote attack vectors.
nvd
CVE-2010-1213P4MEDIUMCVSS 4.3≤ 2.0.5v1.0+38 more2010-07-30
CVE-2010-1213 [MEDIUM] CWE-20 CVE-2010-1213: The importScripts Web Worker method in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, T The importScripts Web Worker method in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not verify that content is valid JavaScript code, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted HTML doc
nvd
CVE-2010-5074P4MEDIUMCVSS 4.3≤ 2.1v1.0+49 more2011-12-07
CVE-2010-5074 [MEDIUM] CWE-362 CVE-2010-5074: The layout engine in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 ex The layout engine in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 executes different code for visited and unvisited links during the processing of Cascading Style Sheets (CSS) token sequences, which makes it easier for remote attackers to obtain sensitive information about visited web pages via a timing attack.
nvd
CVE-2006-1725P4LOWCVSS 2.6fixed in 1.0.12006-04-14
CVE-2006-1725 [LOW] CWE-264 CVE-2006-1725: Mozilla Firefox 1.5 before 1.5.0.2 and SeaMonkey before 1.0.1 causes certain windows to become trans Mozilla Firefox 1.5 before 1.5.0.2 and SeaMonkey before 1.0.1 causes certain windows to become translucent due to an interaction between XUL content windows and the history mechanism, which might allow user-assisted remote attackers to trick users into executing arbitrary code.
nvd
CVE-2007-5339P4MEDIUMCVSS 4.3≤ 1.1.42007-10-21
CVE-2007-5339 [MEDIUM] CWE-20 CVE-2007-5339: Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonke Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption or assert errors.
nvd
CVE-2007-5340P4MEDIUMCVSS 4.3≤ 1.1.42007-10-21
CVE-2007-5340 [MEDIUM] CWE-20 CVE-2007-5340: Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird bef Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption.
nvd
CVE-2006-1732P4MEDIUMCVSS 4.3v1.02006-04-14
CVE-2006-1732 [MEDIUM] CVE-2006-1732: Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to bypass same-origin protections and conduct cross-site scripting (XSS) attacks via unspecified vectors involving the window.controllers array.
nvd
CVE-2006-1731P4MEDIUMCVSS 4.3≤ 1.0v1.02006-04-14
CVE-2006-1731 [MEDIUM] CWE-79 CVE-2006-1731: Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
nvd
CVE-2014-1591P4MEDIUMCVSS 4.3≤ 2.302014-12-11
CVE-2014-1591 [MEDIUM] CWE-199 CVE-2014-1591: Mozilla Firefox 33.0 and SeaMonkey before 2.31 include path strings in CSP violation reports, which Mozilla Firefox 33.0 and SeaMonkey before 2.31 include path strings in CSP violation reports, which allows remote attackers to obtain sensitive information via a web site that receives a report after a redirect.
nvd
CVE-2009-3014P4MEDIUMCVSS 4.3v1.1.172009-08-31
CVE-2009-3014 [MEDIUM] CWE-79 CVE-2009-3014: Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1 Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly handle javascript: URIs in HTML links within 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Loca
nvd
CVE-2012-1964P4MEDIUMCVSS 4.0≤ 2.0.14v1.0+47 more2012-07-18
CVE-2012-1964 [MEDIUM] CVE-2012-1964: The certificate-warning functionality in browser/components/certerror/content/aboutCertError.xhtml i The certificate-warning functionality in browser/components/certerror/content/aboutCertError.xhtml in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.10 does not properly handle attempted clickjacking of the about:certerror page, which allows man-in-the-
nvd
Mozilla Seamonkey vulnerabilities | cvebase