Severity
9.3CRITICALNVD
EPSS
1.6%
top 18.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19
Latest updateMay 13

Description

The ClusterIterator::NextCluster function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages5 packages

NVDmozilla/firefox< 17.0.3+1
NVDmozilla/seamonkey< 2.16
NVDmozilla/thunderbird< 17.0.3
NVDopensuse/opensuse11.4, 12.1, 12.2+2

Also affects: Ubuntu Linux 10.04, 11.10, 12.04, 12.10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hgm6-w6m9-gcfw: The ClusterIterator::NextCluster function in Mozilla Firefox before 192022-05-13
CVEList
CVE-2013-0778: The ClusterIterator::NextCluster function in Mozilla Firefox before 192013-02-19

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2013-02-25
Ubuntu
Firefox vulnerabilities2013-02-20
Red Hat
Mozilla: Use-after-free, out of bounds read, and buffer overflow issues found using Address Sanitizer (MFSA 2013-28)2013-02-19

💬Community

1
Bugzilla
CVE-2013-0777 CVE-2013-0778 CVE-2013-0779 CVE-2013-0781 Mozilla: Use-after-free, out of bounds read, and buffer overflow issues found using Address Sanitizer (MFSA 2013-28)2013-02-16
CVE-2013-0778 — Out-of-bounds Read in Mozilla Firefox | cvebase