CVE-2013-1680
published 2013-05-16CVE-2013-1680: Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6…
PriorityP336critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.54%
92.0th percentile
Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 20.0.1 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | thunderbird | <= 17.0.5 | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird_esr | — | — |
| mozilla | thunderbird_esr | — | — |
| mozilla | thunderbird_esr | — | — |
| mozilla | thunderbird_esr | — | — |
| mozilla | thunderbird_esr | — | — |
| mozilla | thunderbird_esr | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-05-14·CVSS 10.0
CVE-2013-0801 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple memory safety issues were discovered in Firefox. If the user were
tricked into opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking Firefox.
(CVE-2013-0801, CVE-2013-1669)
Cody Crews discovered that some constructors could be used to bypass
restrictions enforced by their Chrome Object Wrapper (COW). An attacker
could exploit this to conduct cross-site scripting (XSS) attacks.
(CVE-2013-1670)
It was discovered that the file input element could expose the full local
path under certain conditions. An attack
Red Hat
Mozilla: Memory corruption found using Address Sanitizer (MFSA 2013-48)
vendor_redhat·2013-05-14·CVSS 10.0
CVE-2013-1680 [CRITICAL] Mozilla: Memory corruption found using Address Sanitizer (MFSA 2013-48)
Mozilla: Memory corruption found using Address Sanitizer (MFSA 2013-48)
Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
Package: thunderbird (Red Hat Enterprise Linux 5) - Affected
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2013-05-14·CVSS 10.0
CVE-2013-0801 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple memory safety issues were discovered in Thunderbird. If the user
were tricked into opening a specially crafted message with scripting
enabled, an attacker could possibly exploit these to cause a denial of
service via application crash, or potentially execute code with the
privileges of the user invoking Thunderbird. (CVE-2013-0801,
CVE-2013-1669)
Cody Crews discovered that some constructors could be used to bypass
restrictions enforced by their Chrome Object Wrapper (COW). If a user had
scripting enabled, an attacker could exploit this to conduct cross-site
scripting (XSS) attacks. (CVE-2013-1670)
A use-after-free was discovered when resizing video content whilst it is
playing. If a
GHSA
GHSA-8p39-8gpr-fr9x: Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox before 21
ghsa_unreviewed·2022-05-17
CVE-2013-1680 [HIGH] CWE-119 GHSA-8p39-8gpr-fr9x: Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox before 21
Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1676 CVE-2013-1677 CVE-2013-1678 CVE-2013-1679 CVE-2013-1680 CVE-2013-1681 Mozilla: Memory corruption found using Address Sanitizer (MFSA 2013-48)
bugzilla·2013-05-14·CVSS 10.0
CVE-2013-1676 [CRITICAL] CVE-2013-1676 CVE-2013-1677 CVE-2013-1678 CVE-2013-1679 CVE-2013-1680 CVE-2013-1681 Mozilla: Memory corruption found using Address Sanitizer (MFSA 2013-48)
CVE-2013-1676 CVE-2013-1677 CVE-2013-1678 CVE-2013-1679 CVE-2013-1680 CVE-2013-1681 Mozilla: Memory corruption found using Address Sanitizer (MFSA 2013-48)
Security researcher Abhishek Arya (Inferno) of the Google Chrome Security Team used the Address Sanitizer tool to discover a series of use-after-free, out of bounds read, and invalid write problems rated as moderate to critical as security issues in shipped software. Some of these issues are potentially exploitable, allowing for remote code execution. We would also like to thank Abhishek for reporting additional use-after-free flaws in dir=auto code introduced during Firefox development. These were fixed before general release.
External Reference:
http://www.mozilla.org/security/announce/2013/mfsa2013-48.html
Acknowledgements:
Re
Bugzilla
CVE-2011-1680 ncpfs: ncpmount does not remove /etc/mtab~ lock file after failed mount entry addition
bugzilla·2011-04-12·CVSS 4.4
CVE-2011-1680 [MEDIUM] CVE-2011-1680 ncpfs: ncpmount does not remove /etc/mtab~ lock file after failed mount entry addition
CVE-2011-1680 ncpfs: ncpmount does not remove /etc/mtab~ lock file after failed mount entry addition
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1680 to
the following vulnerability:
Name: CVE-2011-1680
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1680
Assigned: 20110409
Reference: http://openwall.com/lists/oss-security/2011/03/04/9
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=688980
ncpmount in ncpfs 2.2.6 and earlier does not remove the /etc/mtab~
lock file after a failed attempt to add a mount entry, which has
unspecified impact and local attack vectors.
Discussion:
Created ncpfs tracking bugs for this issue
Affects: fedora-all [bug 695935]
---
ncpfs package has been orphaned and retired since 12 Mar 2013.
Please see:
-> https://
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0820.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0821.htmlhttp://www.debian.org/security/2013/dsa-2699http://www.mandriva.com/security/advisories?name=MDVSA-2013:165http://www.mozilla.org/security/announce/2013/mfsa2013-48.htmlhttp://www.securityfocus.com/bid/59861http://www.ubuntu.com/usn/USN-1822-1http://www.ubuntu.com/usn/USN-1823-1https://bugzilla.mozilla.org/show_bug.cgi?id=850931https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17031http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0820.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0821.htmlhttp://www.debian.org/security/2013/dsa-2699http://www.mandriva.com/security/advisories?name=MDVSA-2013:165http://www.mozilla.org/security/announce/2013/mfsa2013-48.htmlhttp://www.securityfocus.com/bid/59861http://www.ubuntu.com/usn/USN-1822-1http://www.ubuntu.com/usn/USN-1823-1https://bugzilla.mozilla.org/show_bug.cgi?id=850931https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17031
2013-05-16
Published