vendor:
SeaMonkey
by:
athos
7.5
CVSS
HIGH
Denial of Service
20
CWE
Product Name: SeaMonkey
Affected Version From: 1.1.14
Affected Version To: 1.1.14
Patch Exists: YES
Related CWE: N/A
CPE: a:seamonkey:seamonkey
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 8.10, Slackware 12.2
2009
SeaMonkey <= 1.1.14 (marquee) Denial of Service Exploit
SeaMonkey <= 1.1.14 is vulnerable to a Denial of Service attack when a maliciously crafted HTML file is opened. The exploit creates an HTML file with a large number of <marquee> tags, which causes the browser to crash when the file is opened.
Mitigation:
Upgrade to the latest version of SeaMonkey.