Seamonkey

Vendor:

First CVE: Feb 2, 2006 · Active for 20 years

707
Total CVEs
More Total CVEs than 100% of tracked products
70.7
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.1%
KEV Rate
Higher KEV Rate than 95% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Seamonkey over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 2, 2006
20 years ago
Most Recent CVE
May 21, 2015
4,082 days ago

CVE Severity & Scoring

Seamonkey707 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local1 (0.1%)
Network37 (5.2%)
Unknown669 (94.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (4.8%)
High4 (0.6%)
Unknown669 (94.6%)
User Interaction
None25 (3.5%)
Unknown669 (94.6%)
Required13 (1.8%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None38 (5.4%)
Unknown669 (94.6%)

Top CVEs

Signals from CVEs in this product scope (707 CVEs).

707 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled,
Oct 28, 20109.897YESYES
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbit
Mar 19, 20149.887NOYES
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attac
Jun 30, 201110.086NOYES
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors re
May 7, 201110.086NOYES
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which allows remote attackers to execute arbi
May 7, 201110.085NOYES
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vec
Mar 19, 20149.884NOYES
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via s
Mar 15, 20135.980NOYES
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaM
Jan 13, 20139.380NOYES
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (windo
Jul 27, 20067.580NOYES
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, which allows remote attackers to c
Dec 21, 20117.579NOYES

Exploit Exposure

Signals from CVEs in this product scope (707 CVEs).

CISA KEV
1 CVE
0.1% of CVEs· 95th percentile
Metasploit
18 CVEs
2.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
40 CVEs
5.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (707 CVEs).

Media Mentions

Signals from CVEs in this product scope (707 CVEs).

Top CNAs Publishing CVEs For Seamonkey

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.9.1207.16.6%02
2.9567.55.2%02
2.8547.44.9%02
2.7.2607.44.8%02
2.7.1607.44.8%02
2.7717.34.5%02
2.6.1707.24.5%02
2.6707.24.5%02
2.5727.24.6%03
2.4.1717.24.4%02
2.4727.24.4%02
2.3513.799.9%01
2.3.3777.24.3%02
2.3.2727.14.4%02
2.3.1727.14.4%02
2.3727.14.4%02
2.2617.516.2%00
2.2528.014.1%00
2.2417.516.2%00
2.2317.516.2%00