7.1
CVSSv2

CVE-2009-3385

Published: 23/03/2010 Updated: 19/09/2017
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

The mail component in Mozilla SeaMonkey prior to 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted remote malicious users to obtain sensitive information via crafted content in an IFRAME element in an HTML e-mail message, as demonstrated by a Flash object that sends arbitrary local files during a reply or forward operation.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1.11

mozilla seamonkey 1.1.4

mozilla seamonkey 1.1.3

mozilla seamonkey 1.0.9

mozilla seamonkey 1.0.8

mozilla seamonkey 1.0

mozilla seamonkey 1.1.15

mozilla seamonkey 1.1.14

mozilla seamonkey 1.1.13

mozilla seamonkey 1.1.6

mozilla seamonkey 1.1.5

mozilla seamonkey 1.0.3

mozilla seamonkey 1.0.2

mozilla seamonkey 1.0.1

mozilla seamonkey 1.1.17

mozilla seamonkey 1.1.16

mozilla seamonkey 1.1.8

mozilla seamonkey 1.1.7

mozilla seamonkey 1.1

mozilla seamonkey 1.0.5

mozilla seamonkey 1.0.4

mozilla seamonkey 1.1.1

mozilla seamonkey

mozilla seamonkey 1.1.10

mozilla seamonkey 1.1.9

mozilla seamonkey 1.1.2

mozilla seamonkey 1.0.7

mozilla seamonkey 1.0.6

Vendor Advisories

Mozilla Foundation Security Advisory 2010-06 Scriptable plugin execution in SeaMonkey mail Announced March 16, 2010 Reporter Georgi Guninski Impact Critical Products SeaMonkey Fixed in ...