Vulnerabilities > Mozilla > Seamonkey > 2.8

DATE CVE VULNERABILITY TITLE RISK
2012-04-25 CVE-2012-0467 Memory Corruption vulnerability in Mozilla Firefox/Thunderbird/SeaMonkey
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
network
low complexity
mozilla
critical
10.0
2012-03-30 CVE-2011-3062 Incorrect Calculation vulnerability in Google Chrome
Off-by-one error in the OpenType Sanitizer in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted OpenType file.
6.8
2011-08-18 CVE-2011-2984 Code Injection vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.
network
low complexity
mozilla CWE-94
critical
10.0
2011-08-18 CVE-2011-2983 Information Exposure vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and possibly other products does not properly handle the RegExp.input property, which allows remote attackers to bypass the Same Origin Policy and read data from a different domain via a crafted web site, possibly related to a use-after-free.
network
mozilla CWE-200
4.3
2011-08-18 CVE-2011-2378 Code Injection vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
The appendChild function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, SeaMonkey 2.x, and possibly other products does not properly handle DOM objects, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to dereferencing of a "dangling pointer."
network
low complexity
mozilla CWE-94
critical
10.0
2011-03-11 CVE-2011-1187 Information Exposure vulnerability in Google Chrome
Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."
network
low complexity
google mozilla CWE-200
5.0