CVE-2013-0789
published 2013-04-03CVE-2013-0789: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0 and SeaMonkey before 2.17 allow remote attackers to cause a denial of…
PriorityP340critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.44%
90.3th percentile
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0 and SeaMonkey before 2.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsContentUtils::HoldJSObjects function and the nsAutoPtr class, and other vectors.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 19.0.2 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 2.17 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Unity Firefox Extension update
vendor_ubuntu·2013-04-04·CVSS 10.0
[CRITICAL] Unity Firefox Extension update
Title: Unity Firefox Extension update
Summary: This update provides a compatible version of Unity Firefox Extension for
Firefox 20.
USN-1786-1 fixed vulnerabilities in Firefox. This update provides the
corresponding update for Unity Firefox Extension.
Original advisory details:
Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan
Sreckovic, Joe Drew, Andrew McCreight, Randell Jesup, Gary Kwong and
Mats Palmgren discovered multiple memory safety issues affecting Firefox.
If the user were tricked into opening a specially crafted page, an
attacker could possibly exploit these to cause a denial of service via
application crash, or potentially execute code with the privileges of the
user invoking Firefox. (CVE-2013-0788, CVE-2013-0789)
Ambroz Bizjak discovered an out-of-boun
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-04-04·CVSS 10.0
CVE-2013-0788 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan
Sreckovic, Joe Drew, Andrew McCreight, Randell Jesup, Gary Kwong and
Mats Palmgren discovered multiple memory safety issues affecting Firefox.
If the user were tricked into opening a specially crafted page, an
attacker could possibly exploit these to cause a denial of service via
application crash, or potentially execute code with the privileges of the
user invoking Firefox. (CVE-2013-0788, CVE-2013-0789)
Ambroz Bizjak discovered an out-of-bounds array read in the
CERT_DecodeCertPackage function of the Network Security Services (NSS)
libary when decoding certain certificates. An attacker
Red Hat
Mozilla: Miscellaneous memory safety hazards (rv:20.0) (MFSA 2013-30)
vendor_redhat·2013-04-02·CVSS 10.0
CVE-2013-0789 [CRITICAL] Mozilla: Miscellaneous memory safety hazards (rv:20.0) (MFSA 2013-30)
Mozilla: Miscellaneous memory safety hazards (rv:20.0) (MFSA 2013-30)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0 and SeaMonkey before 2.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsContentUtils::HoldJSObjects function and the nsAutoPtr class, and other vectors.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not
GHSA
GHSA-2c67-fjgj-8c9f: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20
ghsa_unreviewed·2022-05-17
CVE-2013-0789 [HIGH] GHSA-2c67-fjgj-8c9f: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0 and SeaMonkey before 2.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsContentUtils::HoldJSObjects function and the nsAutoPtr class, and other vectors.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00012.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-30.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=808736https://bugzilla.mozilla.org/show_bug.cgi?id=815315https://bugzilla.mozilla.org/show_bug.cgi?id=817841https://bugzilla.mozilla.org/show_bug.cgi?id=824643https://bugzilla.mozilla.org/show_bug.cgi?id=824856https://bugzilla.mozilla.org/show_bug.cgi?id=827596https://bugzilla.mozilla.org/show_bug.cgi?id=830595https://bugzilla.mozilla.org/show_bug.cgi?id=831055https://bugzilla.mozilla.org/show_bug.cgi?id=835499https://bugzilla.mozilla.org/show_bug.cgi?id=837714https://bugzilla.mozilla.org/show_bug.cgi?id=839209https://bugzilla.mozilla.org/show_bug.cgi?id=842300https://bugzilla.mozilla.org/show_bug.cgi?id=849014https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17079http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00012.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-30.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=808736https://bugzilla.mozilla.org/show_bug.cgi?id=815315https://bugzilla.mozilla.org/show_bug.cgi?id=817841https://bugzilla.mozilla.org/show_bug.cgi?id=824643https://bugzilla.mozilla.org/show_bug.cgi?id=824856https://bugzilla.mozilla.org/show_bug.cgi?id=827596https://bugzilla.mozilla.org/show_bug.cgi?id=830595https://bugzilla.mozilla.org/show_bug.cgi?id=831055https://bugzilla.mozilla.org/show_bug.cgi?id=835499https://bugzilla.mozilla.org/show_bug.cgi?id=837714https://bugzilla.mozilla.org/show_bug.cgi?id=839209https://bugzilla.mozilla.org/show_bug.cgi?id=842300https://bugzilla.mozilla.org/show_bug.cgi?id=849014https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17079
2013-04-03
Published