CVE-2013-0801
published 2013-05-16CVE-2013-0801: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and…
PriorityP336critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.39%
91.8th percentile
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 20.0.1 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | thunderbird | <= 17.0.5 | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird_esr | — | — |
| mozilla | thunderbird_esr | — | — |
| mozilla | thunderbird_esr | — | — |
| mozilla | thunderbird_esr | — | — |
| mozilla | thunderbird_esr | — | — |
| mozilla | thunderbird_esr | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-05-14·CVSS 10.0
CVE-2013-0801 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple memory safety issues were discovered in Firefox. If the user were
tricked into opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking Firefox.
(CVE-2013-0801, CVE-2013-1669)
Cody Crews discovered that some constructors could be used to bypass
restrictions enforced by their Chrome Object Wrapper (COW). An attacker
could exploit this to conduct cross-site scripting (XSS) attacks.
(CVE-2013-1670)
It was discovered that the file input element could expose the full local
path under certain conditions. An attack
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2013-05-14·CVSS 10.0
CVE-2013-0801 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple memory safety issues were discovered in Thunderbird. If the user
were tricked into opening a specially crafted message with scripting
enabled, an attacker could possibly exploit these to cause a denial of
service via application crash, or potentially execute code with the
privileges of the user invoking Thunderbird. (CVE-2013-0801,
CVE-2013-1669)
Cody Crews discovered that some constructors could be used to bypass
restrictions enforced by their Chrome Object Wrapper (COW). If a user had
scripting enabled, an attacker could exploit this to conduct cross-site
scripting (XSS) attacks. (CVE-2013-1670)
A use-after-free was discovered when resizing video content whilst it is
playing. If a
Red Hat
Mozilla: Miscellaneous memory safety hazards (rv:17.0.6) (MFSA 2013-41)
vendor_redhat·2013-05-14·CVSS 10.0
CVE-2013-0801 [CRITICAL] Mozilla: Miscellaneous memory safety hazards (rv:17.0.6) (MFSA 2013-41)
Mozilla: Miscellaneous memory safety hazards (rv:17.0.6) (MFSA 2013-41)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Package: thunderbird (Red Hat Enterprise Linux 5) - Affected
GHSA
GHSA-vxg5-7h3v-fpwg: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21
ghsa_unreviewed·2022-05-17
CVE-2013-0801 [HIGH] GHSA-vxg5-7h3v-fpwg: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0820.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0821.htmlhttp://www.debian.org/security/2013/dsa-2699http://www.mandriva.com/security/advisories?name=MDVSA-2013:165http://www.mozilla.org/security/announce/2013/mfsa2013-41.htmlhttp://www.securityfocus.com/bid/59855http://www.ubuntu.com/usn/USN-1822-1http://www.ubuntu.com/usn/USN-1823-1https://bugzilla.mozilla.org/show_bug.cgi?id=787283https://bugzilla.mozilla.org/show_bug.cgi?id=808402https://bugzilla.mozilla.org/show_bug.cgi?id=849597https://bugzilla.mozilla.org/show_bug.cgi?id=852315https://bugzilla.mozilla.org/show_bug.cgi?id=864558https://bugzilla.mozilla.org/show_bug.cgi?id=866544https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17062http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0820.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0821.htmlhttp://www.debian.org/security/2013/dsa-2699http://www.mandriva.com/security/advisories?name=MDVSA-2013:165http://www.mozilla.org/security/announce/2013/mfsa2013-41.htmlhttp://www.securityfocus.com/bid/59855http://www.ubuntu.com/usn/USN-1822-1http://www.ubuntu.com/usn/USN-1823-1https://bugzilla.mozilla.org/show_bug.cgi?id=787283https://bugzilla.mozilla.org/show_bug.cgi?id=808402https://bugzilla.mozilla.org/show_bug.cgi?id=849597https://bugzilla.mozilla.org/show_bug.cgi?id=852315https://bugzilla.mozilla.org/show_bug.cgi?id=864558https://bugzilla.mozilla.org/show_bug.cgi?id=866544https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17062
2013-05-16
Published