Severity
9.3CRITICALNVD
EPSS
3.2%
top 13.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateMay 13

Description

Buffer overflow in the CharDistributionAnalysis::HandleOneChar function in Mozilla Firefox before 18.0, Thunderbird before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via a crafted document.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages8 packages

NVDmozilla/firefox17.017.0.2+2
NVDmozilla/seamonkey< 2.15
NVDmozilla/thunderbird< 17.0.2
NVDmozilla/thunderbird_esr17.017.0.2+1
NVDopensuse/opensuse11.4, 12.1, 12.2+2

Also affects: Ubuntu Linux 10.04, 11.10, 12.04, 12.10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-79gw-xgrr-5rc7: Buffer overflow in the CharDistributionAnalysis::HandleOneChar function in Mozilla Firefox before 182022-05-13
CVEList
CVE-2013-0760: Buffer overflow in the CharDistributionAnalysis::HandleOneChar function in Mozilla Firefox before 182013-01-13

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2013-01-09
Ubuntu
Thunderbird vulnerabilities2013-01-09
Red Hat
Mozilla: Use-after-free and buffer overflow issues found using Address Sanitizer (MFSA 2013-02)2013-01-08

💬Community

1
Bugzilla
CVE-2013-0760 CVE-2013-0761 CVE-2013-0763 CVE-2013-0771 Mozilla: Use-after-free and buffer overflow issues found using Address Sanitizer (MFSA 2013-02)2013-01-04
CVE-2013-0760 — Classic Buffer Overflow in Mozilla | cvebase