CVE-2013-0765Mozilla Firefox vulnerability

7 documents7 sources
Severity
9.3CRITICALNVD
EPSS
0.8%
top 26.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19
Latest updateMay 13

Description

Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 do not prevent multiple wrapping of WebIDL objects, which allows remote attackers to bypass intended access restrictions via unspecified vectors.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

NVDmozilla/firefox< 19.0
NVDmozilla/seamonkey< 2.16
NVDopensuse/opensuse11.4, 12.1, 12.2+2

Also affects: Ubuntu Linux 10.04, 11.10, 12.04, 12.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-gv73-63gr-q7mh: Mozilla Firefox before 192022-05-13
Project0
Attacking ECMAScript Engines with Redefinition - Project Zero2015-08-01
CVEList
CVE-2013-0765: Mozilla Firefox before 192013-02-19

📋Vendor Advisories

2
Ubuntu
Firefox vulnerabilities2013-02-20
Red Hat
Mozilla: Wrapped WebIDL objects can be wrapped again (MFSA 2013-23)2013-02-19

💬Community

1
Bugzilla
CVE-2013-0765 Mozilla: Wrapped WebIDL objects can be wrapped again (MFSA 2013-23)2013-02-16
CVE-2013-0765 — Mozilla Firefox vulnerability | cvebase