Vulnerability Database

296,213

Total vulnerabilities in the database

CVE-2009-3385

The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted remote attackers to obtain sensitive information via crafted content in an IFRAME element in an HTML e-mail message, as demonstrated by a Flash object that sends arbitrary local files during a reply or forward operation.

  • Published: Mar 23, 2010
  • Updated: Apr 13, 2023
  • CVE: CVE-2009-3385
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.1
  • AV:N/AC:M/Au:N/C:C/I:N/A:N

CWEs:

Software From Fixed in
mozilla / seamonkey 1.1.10 1.1.10.x
mozilla / seamonkey 1.0.3 1.0.3.x
mozilla / seamonkey 1.1.8 1.1.8.x
mozilla / seamonkey 1.0.1 1.0.1.x
mozilla / seamonkey 1.1.7 1.1.7.x
mozilla / seamonkey 1.0.6 1.0.6.x
mozilla / seamonkey 1.0.9 1.0.9.x
mozilla / seamonkey 1.1.3 1.1.3.x
mozilla / seamonkey 1.0 1.0.x
mozilla / seamonkey 1.1.17 1.1.17.x
mozilla / seamonkey 1.1.5 1.1.5.x
mozilla / seamonkey 1.0.7 1.0.7.x
mozilla / seamonkey 1.0-beta 1.0-beta.x
mozilla / seamonkey 1.1-alpha 1.1-alpha.x
mozilla / seamonkey 1.0-alpha 1.0-alpha.x
mozilla / seamonkey 1.1.12 1.1.12.x
mozilla / seamonkey 1.1 1.1.x
mozilla / seamonkey 1.1.14 1.1.14.x
mozilla / seamonkey 1.1.2 1.1.2.x
mozilla / seamonkey 1.0.2 1.0.2.x
mozilla / seamonkey 1.0.8 1.0.8.x
mozilla / seamonkey 1.1.11 1.1.11.x
mozilla / seamonkey 1.1-beta 1.1-beta.x
mozilla / seamonkey 1.1.1 1.1.1.x
mozilla / seamonkey 1.0.5 1.0.5.x
mozilla / seamonkey 1.1.15 1.1.15.x
mozilla / seamonkey 1.1.6 1.1.6.x
mozilla / seamonkey - 1.1.18.x
mozilla / seamonkey 1.1.16 1.1.16.x
mozilla / seamonkey 1.0.4 1.0.4.x
mozilla / seamonkey 1.1.9 1.1.9.x
mozilla / seamonkey 1.1.13 1.1.13.x
mozilla / seamonkey 1.1.4 1.1.4.x