← Back

Seamonkey

seamonkey

Vendor: Mozilla • 704 CVEs

CVEs (704)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
MozillaOpensuse+1 more
8Firefox
Linux Enterprise DesktopLinux Enterprise Server+5 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving the setting of Casca...Show more
Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving the setting of Cascading Style Sheets (CSS) properties in conjunction with SVG text.Show less
5Canonical
MozillaOpensuse+2 more
13Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+10 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Integer overflow in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to...Show more
Integer overflow in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (invalid write operation) via crafted data.Show less
5Canonical
MozillaOpensuse+2 more
13Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+10 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
The texImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not prope...Show more
The texImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly interact with Mesa drivers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via function calls involving certain values of the level parameter.Show less
5Canonical
MozillaOpensuse+2 more
14Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+11 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 on Mac OS X allows remote attackers to...Show more
Use-after-free vulnerability in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 on Mac OS X allows remote attackers to execute arbitrary code via an HTML document.Show less
6Canonical
DebianMozilla+3 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+11 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the nsWindow::OnExposeEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14...Show more
Heap-based buffer overflow in the nsWindow::OnExposeEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via unspecified vectors.Show less
4Canonical
MozillaOpensuse+1 more
8Firefox
Linux Enterprise DesktopLinux Enterprise Server+5 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Use-after-free vulnerability in the BuildTextRunsScanner::BreakSink::SetBreaks function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code...Show more
Use-after-free vulnerability in the BuildTextRunsScanner::BreakSink::SetBreaks function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.Show less
4Canonical
MozillaOpensuse+1 more
9Firefox
Linux Enterprise DesktopLinux Enterprise Server+6 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or ca...Show more
Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.Show less
6Canonical
DebianMozilla+3 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+11 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Use-after-free vulnerability in the gfxFont::GetFontEntry function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14...Show more
Use-after-free vulnerability in the gfxFont::GetFontEntry function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.Show less
5Canonical
MozillaOpensuse+2 more
13Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+10 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Use-after-free vulnerability in the nsPlaintextEditor::FireClipboardEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMon...Show more
Use-after-free vulnerability in the nsPlaintextEditor::FireClipboardEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.Show less
5Canonical
MozillaOpensuse+2 more
13Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+10 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey b...Show more
Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-5840.Show less
4Canonical
MozillaOpensuse+1 more
9Firefox
Linux Enterprise DesktopLinux Enterprise Server+6 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Use-after-free vulnerability in the nsEditor::FindNextLeafNode function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a deni...Show more
Use-after-free vulnerability in the nsEditor::FindNextLeafNode function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.Show less
4Canonical
MozillaOpensuse+1 more
8Firefox
Linux Enterprise DesktopLinux Enterprise Server+5 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial o...Show more
Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.Show less
5Canonical
MozillaOpensuse+2 more
13Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+10 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do not prevent use of a "top" frame name-attribute value to access the...Show more
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do not prevent use of a "top" frame name-attribute value to access the location property, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a binary plugin.Show less
4Canonical
MozillaOpensuse+1 more
8Firefox
Linux Enterprise DesktopLinux Enterprise Server+5 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote attackers to bypass inten...Show more
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote attackers to bypass intended chrome-only restrictions on reading DOM object properties via a crafted web site.Show less
6Canonical
DebianMozilla+3 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+11 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly handl...Show more
The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly handle a ~ (tilde) character in proximity to a chunk delimiter, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document.Show less
4Canonical
MozillaOpensuse+1 more
8Firefox
Linux Enterprise DesktopLinux Enterprise Server+5 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XMLHttpRequest objects created in sandboxes, which allows remote attacker...Show more
Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XMLHttpRequest objects created in sandboxes, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks or obtain sensitive information by leveraging a sandboxed add-on.Show less
4Canonical
MozillaOpensuse+1 more
8Firefox
Linux Enterprise DesktopLinux Enterprise Server+5 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
The str_unescape function in the JavaScript engine in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (memory...Show more
The str_unescape function in the JavaScript engine in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.Show less
5Canonical
MozillaOpensuse+2 more
13Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+10 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the image::RasterImage::DrawFrameTo function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey befo...Show more
Heap-based buffer overflow in the image::RasterImage::DrawFrameTo function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code via a crafted GIF image.Show less
6Canonical
DebianMozilla+3 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+11 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The evalInSandbox implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 uses an incorrect context during t...Show more
The evalInSandbox implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 uses an incorrect context during the handling of JavaScript code that sets the location.href property, which allows remote attackers to conduct cross-site scripting (XSS) attacks or read arbitrary files by leveraging a sandboxed add-on.Show less
5Canonical
MozillaOpensuse+2 more
13Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+10 more
Apr 29, 2026
Oct 29, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read...Show more
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.Show less