CVE-2013-0773Mozilla Firefox vulnerability

7 documents6 sources
Severity
9.3CRITICALNVD
EPSS
1.5%
top 18.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19
Latest updateMay 13

Description

The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent modifications to a prototype, which allows remote attackers to obtain sensitive information from chrome objects or possibly execute arbitrary JavaScript code with chrome privileges via a crafted web site.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages5 packages

NVDmozilla/firefox< 17.0.3+1
NVDmozilla/thunderbird< 17.0.3
NVDmozilla/seamonkey< 2.16
NVDopensuse/opensuse11.4, 12.1, 12.2+2

Also affects: Debian Linux 7.0, Ubuntu Linux 10.04, 11.10, 12.04, 12.10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9w3c-59m9-46f5: The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox before 192022-05-13
CVEList
CVE-2013-0773: The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox before 192013-02-19

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2013-02-25
Ubuntu
Firefox vulnerabilities2013-02-20
Red Hat
Mozilla: Web content bypass of COW and SOW security wrappers (MFSA 2013-24)2013-02-19

💬Community

1
Bugzilla
CVE-2013-0773 Mozilla: Web content bypass of COW and SOW security wrappers (MFSA 2013-24)2013-02-16
CVE-2013-0773 — Mozilla Firefox vulnerability | cvebase