CVE-2013-0775
published 2013-02-19CVE-2013-0775: Use-after-free vulnerability in the nsImageLoadingContent::OnStopContainer function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird…
PriorityP341critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.50%
87.8th percentile
Use-after-free vulnerability in the nsImageLoadingContent::OnStopContainer function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code via crafted web script.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| mozilla | firefox | < 17.0.3 | 17.0.3 |
| mozilla | firefox | < 19.0 | 19.0 |
| mozilla | seamonkey | < 2.16 | 2.16 |
| mozilla | thunderbird | < 17.0.3 | 17.0.3 |
| mozilla | thunderbird_esr | < 17.0.3 | 17.0.3 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_aus | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox regression
vendor_ubuntu·2013-03-01·CVSS 9.3
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: Due to a regression, Firefox might crash or freeze under normal use.
USN-1729-1 fixed vulnerabilities in Firefox. This update introduced a
regression which sometimes resulted in freezes and crashes when using
multiple tabs with images displayed. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Olli Pettay, Christoph Diehl, Gary Kwong, Jesse Ruderman, Andrew McCreight,
Joe Drew, Wayne Mery, Alon Zakai, Christian Holler, Gary Kwong, Luke
Wagner, Terrence Cole, Timothy Nikkel, Bill McCloskey, and Nicolas Pierron
discovered multiple memory safety issues affecting Firefox. If the user
were tricked into opening a specially crafted page, an attacker could
possibly exploit these to cause a denial of service via ap
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2013-02-25·CVSS 9.3
CVE-2013-0773 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Bobby Holley discovered vulnerabilities in Chrome Object Wrappers (COW) and
System Only Wrappers (SOW). If a user were tricked into opening a specially
crafted page and had scripting enabled, a remote attacker could exploit
this to bypass security protections to obtain sensitive information or
potentially execute code with the privileges of the user invoking
Thunderbird. (CVE-2013-0773)
Frederik Braun discovered that Thunderbird made the location of the active
browser profile available to JavaScript workers. Scripting for Thunderbird
is disabled by default in Ubuntu. (CVE-2013-0774)
A use-after-free vulnerability was discovered in Thunderbird. An attacker
could potentially exploit this to exe
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-02-20·CVSS 9.3
CVE-2013-0765 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it opened a
malicious website.
Olli Pettay, Christoph Diehl, Gary Kwong, Jesse Ruderman, Andrew McCreight,
Joe Drew, Wayne Mery, Alon Zakai, Christian Holler, Gary Kwong, Luke
Wagner, Terrence Cole, Timothy Nikkel, Bill McCloskey, and Nicolas Pierron
discovered multiple memory safety issues affecting Firefox. If the user
were tricked into opening a specially crafted page, an attacker could
possibly exploit these to cause a denial of service via application crash.
(CVE-2013-0783, CVE-2013-0784)
Atte Kettunen discovered that Firefox could perform an out-of-bounds read
while rendering GIF format images. An attacker could exploit this to crash
Firefox. (CVE-2013-0772)
Boris Zbarsky disco
Red Hat
Mozilla: Use-after-free in nsImageLoadingContent (MFSA 2013-26)
vendor_redhat·2013-02-19·CVSS 9.3
CVE-2013-0775 [CRITICAL] CWE-416 Mozilla: Use-after-free in nsImageLoadingContent (MFSA 2013-26)
Mozilla: Use-after-free in nsImageLoadingContent (MFSA 2013-26)
Use-after-free vulnerability in the nsImageLoadingContent::OnStopContainer function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code via crafted web script.
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
GHSA
GHSA-vf72-86r8-4gfp: Use-after-free vulnerability in the nsImageLoadingContent::OnStopContainer function in Mozilla Firefox before 19
ghsa_unreviewed·2022-05-13
CVE-2013-0775 [HIGH] CWE-416 GHSA-vf72-86r8-4gfp: Use-after-free vulnerability in the nsImageLoadingContent::OnStopContainer function in Mozilla Firefox before 19
Use-after-free vulnerability in the nsImageLoadingContent::OnStopContainer function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code via crafted web script.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.htmlhttp://lists.opensuse.org/opensuse-updates/2013-02/msg00062.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0271.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0272.htmlhttp://www.debian.org/security/2013/dsa-2699http://www.mozilla.org/security/announce/2013/mfsa2013-26.htmlhttp://www.ubuntu.com/usn/USN-1729-1http://www.ubuntu.com/usn/USN-1729-2http://www.ubuntu.com/usn/USN-1748-1https://bugzilla.mozilla.org/show_bug.cgi?id=831095https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16950http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.htmlhttp://lists.opensuse.org/opensuse-updates/2013-02/msg00062.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0271.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0272.htmlhttp://www.debian.org/security/2013/dsa-2699http://www.mozilla.org/security/announce/2013/mfsa2013-26.htmlhttp://www.ubuntu.com/usn/USN-1729-1http://www.ubuntu.com/usn/USN-1729-2http://www.ubuntu.com/usn/USN-1748-1https://bugzilla.mozilla.org/show_bug.cgi?id=831095https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16950
2013-02-19
Published