CVE-2013-1698
published 2013-06-26CVE-2013-1698: The getUserMedia permission implementation in Mozilla Firefox before 22.0 references the URL of a top-level document instead of the URL of a specific page…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.49%
71.5th percentile
The getUserMedia permission implementation in Mozilla Firefox before 22.0 references the URL of a top-level document instead of the URL of a specific page, which makes it easier for remote attackers to trick users into permitting camera or microphone access via a crafted web site that uses IFRAME elements.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 21.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu10.0CRITICAL
vendor_cisco7.8HIGH
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Resource Reservation Protocol Interface Queue Wedge Vulnerability
vendor_cisco·2013-09-25·CVSS 7.8
CVE-2013-5478 [HIGH] CWE-20 Cisco IOS Software Resource Reservation Protocol Interface Queue Wedge Vulnerability
Cisco IOS Software Resource Reservation Protocol Interface Queue Wedge Vulnerability
A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger an interface queue wedge on the affected device.
The vulnerability is due to improper parsing of UDP RSVP packets. An attacker could exploit this vulnerability by sending UDP port 1698 RSVP packets to the vulnerable device. An exploit could cause Cisco IOS Software and Cisco IOS XE Software to incorrectly process incoming packets, resulting in an interface queue wedge, which can lead to loss of connectivity, loss of routing protocol adjacency, and other denial of service (DoS) conditions.
Cisco has released software updates that ad
Ubuntu
Firefox regression
vendor_ubuntu·2013-07-03·CVSS 10.0
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: USN-1890-1 introduced a regression in Firefox.
USN-1890-1 fixed vulnerabilities in Firefox. This update introduced a
regression which sometimes resulted in Firefox using the wrong network
proxy settings. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple memory safety issues were discovered in Firefox. If the user were
tricked into opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2013-1682, CVE-2013-1683)
Abhishek Arya discovered multiple use-after-free bugs. If the user were
tricked into opening a specially crafted page, an attac
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-06-26·CVSS 10.0
CVE-2013-1682 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple memory safety issues were discovered in Firefox. If the user were
tricked into opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2013-1682, CVE-2013-1683)
Abhishek Arya discovered multiple use-after-free bugs. If the user were
tricked into opening a specially crafted page, an attacker could possibly
exploit these to execute arbitrary code with the privileges of the user
invoking Firefox. (CVE-2013-1684, CVE-2013-1685, CVE-2013-1686)
Mariusz Mlynski discovered that user defined
Red Hat
Mozilla: getUserMedia permission dialog incorrectly displays location (MFSA 2013-60)
vendor_redhat·2013-06-25·CVSS 4.3
CVE-2013-1698 [MEDIUM] Mozilla: getUserMedia permission dialog incorrectly displays location (MFSA 2013-60)
Mozilla: getUserMedia permission dialog incorrectly displays location (MFSA 2013-60)
The getUserMedia permission implementation in Mozilla Firefox before 22.0 references the URL of a top-level document instead of the URL of a specific page, which makes it easier for remote attackers to trick users into permitting camera or microphone access via a crafted web site that uses IFRAME elements.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Cisco
Cisco IOS Software Resource Reservation Protocol Interface Queue Wedge Vulnerability
vendor_cisco
CVE-2013-5478 Cisco IOS Software Resource Reservation Protocol Interface Queue Wedge Vulnerability
CVE-2013-5478: Cisco IOS Software Resource Reservation Protocol Interface Queue Wedge Vulnerability
A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger an interface queue wedge on the affected device. The vulnerability is due to improper parsing of UDP RSVP packets. An attacker could exploit this vulnerability by sending UDP port 1698 RSVP packets to the vulnerable device. An exploit could cause Cisco IOS Software and Cisco IOS XE Software to incorrectly process incoming packets, resulting in an interface queue wedge, which can lead to loss of connectivity, loss of routing protocol adjacency, and other denial of service (DoS) conditions. Cisco has released software upd
GHSA
GHSA-xcgp-vxv9-g7g2: The getUserMedia permission implementation in Mozilla Firefox before 22
ghsa_unreviewed·2022-05-17
CVE-2013-1698 [MEDIUM] GHSA-xcgp-vxv9-g7g2: The getUserMedia permission implementation in Mozilla Firefox before 22
The getUserMedia permission implementation in Mozilla Firefox before 22.0 references the URL of a top-level document instead of the URL of a specific page, which makes it easier for remote attackers to trick users into permitting camera or microphone access via a crafted web site that uses IFRAME elements.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-60.htmlhttp://www.ubuntu.com/usn/USN-1890-1https://bugzilla.mozilla.org/show_bug.cgi?id=876044https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16791http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-60.htmlhttp://www.ubuntu.com/usn/USN-1890-1https://bugzilla.mozilla.org/show_bug.cgi?id=876044https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16791
2013-06-26
Published