Vulnerabilities > Mozilla > Seamonkey > High

DATE CVE VULNERABILITY TITLE RISK
2009-12-17 CVE-2009-3987 Information Exposure vulnerability in Mozilla Firefox and Seamonkey
The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed software by making multiple calls that specify the ProgID values of different COM objects.
network
low complexity
mozilla CWE-200
7.8
2009-12-17 CVE-2009-3986 Code Injection vulnerability in Mozilla Firefox and Seamonkey
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window.opener property.
network
high complexity
mozilla CWE-94
7.6
2009-03-05 CVE-2009-0776 Information Exposure vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.
network
mozilla CWE-200
7.1
2008-11-13 CVE-2008-5024 XML Injection (Aka Blind Xpath Injection) vulnerability in multiple products
Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.
network
low complexity
mozilla debian canonical CWE-91
7.5
2008-11-13 CVE-2008-5023 Improper Input Validation vulnerability in multiple products
Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR file.
network
low complexity
mozilla debian canonical CWE-20
7.5
2008-11-13 CVE-2008-5022 Improper Authentication vulnerability in multiple products
The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-origin policy and execute arbitrary script via multiple listeners, which bypass the inner window check.
network
low complexity
mozilla debian canonical CWE-287
7.5
2008-09-24 CVE-2008-4068 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via directory traversal sequences in a resource: URI.
network
low complexity
mozilla debian canonical CWE-22
7.8
2008-09-24 CVE-2008-4060 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2) XSLT.
network
low complexity
mozilla CWE-264
7.5
2008-09-24 CVE-2008-4058 Permissions, Privileges, and Access Controls vulnerability in multiple products
The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to (1) chrome XBL and (2) chrome JS.
network
low complexity
mozilla debian canonical CWE-264
7.5
2008-09-24 CVE-2008-3835 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.
network
low complexity
mozilla CWE-264
7.5