The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted remote attackers to obtain sensitive information via crafted content in an IFRAME element in an HTML e-mail message, as demonstrated by a Flash object that sends arbitrary local files during a reply or forward operation.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade seamonkey-nsprUpgrade seamonkey-develUpgrade seamonkey-mailUpgrade seamonkey-dom-inspectorUpgrade seamonkey-nss-develUpgrade seamonkey-chatUpgrade seamonkey-nspr-develUpgrade seamonkey-js-debuggerUpgrade seamonkeyUpgrade seamonkey-nss | Dec 1, 2016 | Mar 22, 2010 |
| Freebsd | — | Upgrade linux-thunderbirdUpgrade thunderbirdUpgrade linux-seamonkeyUpgrade seamonkey | Dec 10, 2025 | Mar 19, 2010 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.19 | Feb 3, 2012 | Mar 22, 2010 |
| Suse | — | Upgrade seamonkey-venkmanUpgrade seamonkey-mailUpgrade mozillaUpgrade mozilla-dom-inspectorUpgrade seamonkeyUpgrade seamonkey-dom-inspectorUpgrade mozilla-mailUpgrade mozilla-venkmanUpgrade seamonkey-ircUpgrade mozilla-develUpgrade seamonkey-spellcheckerUpgrade mozilla-irc | Feb 17, 2015 | Mar 22, 2010 |
| Ubuntu | — | Upgrade seamonkey | Nov 19, 2024 | Mar 23, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub