CVE-2013-0777
published 2013-02-19CVE-2013-0777: Use-after-free vulnerability in the nsDisplayBoxShadowOuter::Paint function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before…
PriorityP337critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.88%
91.1th percentile
Use-after-free vulnerability in the nsDisplayBoxShadowOuter::Paint function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| mozilla | firefox | < 17.0.3 | 17.0.3 |
| mozilla | firefox | < 19.0 | 19.0 |
| mozilla | seamonkey | < 2.16 | 2.16 |
| mozilla | thunderbird | < 17.0.3 | 17.0.3 |
| mozilla | thunderbird_esr | < 17.0.3 | 17.0.3 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox regression
vendor_ubuntu·2013-03-01·CVSS 9.3
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: Due to a regression, Firefox might crash or freeze under normal use.
USN-1729-1 fixed vulnerabilities in Firefox. This update introduced a
regression which sometimes resulted in freezes and crashes when using
multiple tabs with images displayed. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Olli Pettay, Christoph Diehl, Gary Kwong, Jesse Ruderman, Andrew McCreight,
Joe Drew, Wayne Mery, Alon Zakai, Christian Holler, Gary Kwong, Luke
Wagner, Terrence Cole, Timothy Nikkel, Bill McCloskey, and Nicolas Pierron
discovered multiple memory safety issues affecting Firefox. If the user
were tricked into opening a specially crafted page, an attacker could
possibly exploit these to cause a denial of service via ap
Red Hat
busybox: insecure directory permissions in /dev
vendor_redhat·2013-03-01·CVSS 7.2
CVE-2013-1813 [HIGH] busybox: insecure directory permissions in /dev
busybox: insecure directory permissions in /dev
util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.
Package: busybox (Red Hat Enterprise Linux 5) - Not affected
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2013-02-25·CVSS 9.3
CVE-2013-0773 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Bobby Holley discovered vulnerabilities in Chrome Object Wrappers (COW) and
System Only Wrappers (SOW). If a user were tricked into opening a specially
crafted page and had scripting enabled, a remote attacker could exploit
this to bypass security protections to obtain sensitive information or
potentially execute code with the privileges of the user invoking
Thunderbird. (CVE-2013-0773)
Frederik Braun discovered that Thunderbird made the location of the active
browser profile available to JavaScript workers. Scripting for Thunderbird
is disabled by default in Ubuntu. (CVE-2013-0774)
A use-after-free vulnerability was discovered in Thunderbird. An attacker
could potentially exploit this to exe
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-02-20·CVSS 9.3
CVE-2013-0765 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it opened a
malicious website.
Olli Pettay, Christoph Diehl, Gary Kwong, Jesse Ruderman, Andrew McCreight,
Joe Drew, Wayne Mery, Alon Zakai, Christian Holler, Gary Kwong, Luke
Wagner, Terrence Cole, Timothy Nikkel, Bill McCloskey, and Nicolas Pierron
discovered multiple memory safety issues affecting Firefox. If the user
were tricked into opening a specially crafted page, an attacker could
possibly exploit these to cause a denial of service via application crash.
(CVE-2013-0783, CVE-2013-0784)
Atte Kettunen discovered that Firefox could perform an out-of-bounds read
while rendering GIF format images. An attacker could exploit this to crash
Firefox. (CVE-2013-0772)
Boris Zbarsky disco
Red Hat
Mozilla: Use-after-free, out of bounds read, and buffer overflow issues found using Address Sanitizer (MFSA 2013-28)
vendor_redhat·2013-02-19·CVSS 9.3
CVE-2013-0777 [CRITICAL] CWE-416 Mozilla: Use-after-free, out of bounds read, and buffer overflow issues found using Address Sanitizer (MFSA 2013-28)
Mozilla: Use-after-free, out of bounds read, and buffer overflow issues found using Address Sanitizer (MFSA 2013-28)
Use-after-free vulnerability in the nsDisplayBoxShadowOuter::Paint function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-8rgf-9r53-438g: Use-after-free vulnerability in the nsDisplayBoxShadowOuter::Paint function in Mozilla Firefox before 19
ghsa_unreviewed·2022-05-13
CVE-2013-0777 [HIGH] CWE-416 GHSA-8rgf-9r53-438g: Use-after-free vulnerability in the nsDisplayBoxShadowOuter::Paint function in Mozilla Firefox before 19
Use-after-free vulnerability in the nsDisplayBoxShadowOuter::Paint function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.htmlhttp://lists.opensuse.org/opensuse-updates/2013-02/msg00062.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-28.htmlhttp://www.ubuntu.com/usn/USN-1729-1http://www.ubuntu.com/usn/USN-1729-2http://www.ubuntu.com/usn/USN-1748-1https://bugzilla.mozilla.org/show_bug.cgi?id=798691https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16977http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.htmlhttp://lists.opensuse.org/opensuse-updates/2013-02/msg00062.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-28.htmlhttp://www.ubuntu.com/usn/USN-1729-1http://www.ubuntu.com/usn/USN-1729-2http://www.ubuntu.com/usn/USN-1748-1https://bugzilla.mozilla.org/show_bug.cgi?id=798691https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16977
2013-02-19
Published