cbcvebase.
CVE-2013-0796
published 2013-04-03

CVE-2013-0796: The WebGL subsystem in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and…

PriorityP340critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.95%
94.1th percentile
The WebGL subsystem in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 on Linux does not properly interact with Mesa drivers, which allows remote attackers to execute arbitrary code or cause a denial of service (free of unallocated memory) via unspecified vectors.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianmesa< mesa 8.0.5-7 (bookworm)mesa 8.0.5-7 (bookworm)
mesa3dmesa
mesa3dmesa
mesa3dmesa
mesa3dmesa
mesa3dmesa
mesa3dmesa
mesa3dmesa
mesa3dmesa
mesa3dmesa
mesa3dmesa
mesa3dmesa>= 0 < 8.0.5-78.0.5-7
mesa3dmesa>= 0 < 8.0.5-78.0.5-7
mesa3dmesa>= 0 < 8.0.5-78.0.5-7
mesa3dmesa>= 0 < 8.0.5-78.0.5-7
mozillafirefox< 20.020.0
mozillafirefox>= 17.0 < 17.0.517.0.5
mozillaseamonkey< 2.172.17
mozillathunderbird>= 17.0 < 17.0.517.0.5
mozillathunderbird_esr>= 17.0 < 17.0.517.0.5
opensuseopensuse
opensuseopensuse

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.