SeaMonkey < 1.1.16 Multiple Vulnerabilities

High Nessus Plugin ID 36130


A web browser on the remote host is affected by multiple vulnerabilities.


The installed version of SeaMonkey is earlier than 1.1.16. Such versions are potentially affected by the following security issues :

- An XSL transformation vulnerability can be leveraged with a specially crafted stylesheet to crash the browser or to execute arbitrary code. (MFSA 2009-12)

- Multiple remote memory corruption vulnerabilities exist which can be exploited to execute arbitrary code in the context of the user running the affected application.
(MFSA 2009-14)


Upgrade to SeaMonkey 1.1.16 or later.

See Also

Plugin Details

Severity: High

ID: 36130

File Name: seamonkey_1116.nasl

Version: $Revision: 1.16 $

Type: local

Agent: windows

Family: Windows

Published: 2009/04/10

Modified: 2017/06/12

Dependencies: 20862

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:mozilla:seamonkey

Required KB Items: SeaMonkey/Version

Exploit Available: true

Exploit Ease: Exploits are available

Reference Information

CVE: CVE-2009-1169, CVE-2009-1302, CVE-2009-1303, CVE-2009-1304, CVE-2009-1305

BID: 34656, 34235

OSVDB: 53079, 53960, 53961, 53962, 53963, 53964, 53965, 53966, 53967, 53969, 53970, 53971, 53972

CWE: 16, 399