CVE-2013-1702
published 2013-08-07CVE-2013-1702: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of…
PriorityP339critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.39%
91.8th percentile
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 22.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 2.20 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-42w3-672w-72h2: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23
ghsa_unreviewed·2022-05-17
CVE-2013-1702 [HIGH] GHSA-42w3-672w-72h2: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-08-06·CVSS 10.0
CVE-2013-1701 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Jeff Gilbert, Henrik Skupin, Ben Turner, Christian Holler,
Andrew McCreight, Gary Kwong, Jan Varga and Jesse Ruderman discovered
multiple memory safety issues in Firefox. If the user were tricked in to
opening a specially crafted page, an attacker could possibly exploit these
to cause a denial of service via application crash, or potentially execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1701, CVE-2013-1702)
A use-after-free bug was discovered when the DOM is modified during a
SetBody mutation event. If the user were tricked in to opening a specially
crafted page, an attacker could potentially exploit this to execute
a
Red Hat
Mozilla: Miscellaneous memory safety hazards (rv:23.0) (MFSA 2013-63)
vendor_redhat·2013-08-06·CVSS 10.0
CVE-2013-1702 [CRITICAL] Mozilla: Miscellaneous memory safety hazards (rv:23.0) (MFSA 2013-63)
Mozilla: Miscellaneous memory safety hazards (rv:23.0) (MFSA 2013-63)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Ubuntu
Ubufox and Unity Firefox Extension update
vendor_ubuntu·2013-08-06·CVSS 10.0
[CRITICAL] Ubufox and Unity Firefox Extension update
Title: Ubufox and Unity Firefox Extension update
Summary: This update provides compatible packages for Firefox 23.
USN-1924-1 fixed vulnerabilities in Firefox. This update provides the
corresponding updates for Ubufox and Unity Firefox Extension.
Original advisory details:
Jeff Gilbert, Henrik Skupin, Ben Turner, Christian Holler,
Andrew McCreight, Gary Kwong, Jan Varga and Jesse Ruderman discovered
multiple memory safety issues in Firefox. If the user were tricked in to
opening a specially crafted page, an attacker could possibly exploit these
to cause a denial of service via application crash, or potentially execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1701, CVE-2013-1702)
A use-after-free bug was discovered when the DOM is modified during a
Set
Red Hat
mysql: unspecified unauthenticated DoS vulnerability related to Server (CPU Jan 2013)
vendor_redhat·2013-01-15·CVSS 5.0
CVE-2012-1702 [MEDIUM] mysql: unspecified unauthenticated DoS vulnerability related to Server (CPU Jan 2013)
mysql: unspecified unauthenticated DoS vulnerability related to Server (CPU Jan 2013)
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote attackers to affect availability via unknown vectors.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1702 Mozilla: Miscellaneous memory safety hazards (rv:23.0) (MFSA 2013-63)
bugzilla·2013-08-07·CVSS 10.0
CVE-2013-1702 [CRITICAL] CVE-2013-1702 Mozilla: Miscellaneous memory safety hazards (rv:23.0) (MFSA 2013-63)
CVE-2013-1702 Mozilla: Miscellaneous memory safety hazards (rv:23.0) (MFSA 2013-63)
Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code.
In general these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled, but are potentially a risk in browser or browser-like contexts.
Ben Turner, Christian Holler, Andrew McCreight, Gary Kwong, Jan Varga, and Jesse Ruderman reported memory safety problems and crashes that affect Firefox 22.
External Reference:
http://www.mozilla.org/se
Bugzilla
CVE-2012-1702 mysql: unspecified unauthenticated DoS vulnerability related to Server (CPU Jan 2013)
bugzilla·2013-01-16·CVSS 5.0
CVE-2012-1702 [MEDIUM] CVE-2012-1702 mysql: unspecified unauthenticated DoS vulnerability related to Server (CPU Jan 2013)
CVE-2012-1702 mysql: unspecified unauthenticated DoS vulnerability related to Server (CPU Jan 2013)
An unspecified vulnerability in the server subcomponent of the MySQL protocol component of the Oracle MySQL server allows remote attackers to alter availability via unspecified vectors.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Discussion:
This issue affects the version of the mysql package, as shipped with Red Hat Enterprise Linux 6.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0219 https://rhn.redhat.com/errata/RHSA-2013-0219.html
http://www.mozilla.org/security/announce/2013/mfsa2013-63.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=844088https://bugzilla.mozilla.org/show_bug.cgi?id=854157https://bugzilla.mozilla.org/show_bug.cgi?id=855331https://bugzilla.mozilla.org/show_bug.cgi?id=858060https://bugzilla.mozilla.org/show_bug.cgi?id=861530https://bugzilla.mozilla.org/show_bug.cgi?id=862185https://bugzilla.mozilla.org/show_bug.cgi?id=870200https://bugzilla.mozilla.org/show_bug.cgi?id=874974https://bugzilla.mozilla.org/show_bug.cgi?id=878703https://bugzilla.mozilla.org/show_bug.cgi?id=879139https://bugzilla.mozilla.org/show_bug.cgi?id=893684https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18876http://www.mozilla.org/security/announce/2013/mfsa2013-63.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=844088https://bugzilla.mozilla.org/show_bug.cgi?id=854157https://bugzilla.mozilla.org/show_bug.cgi?id=855331https://bugzilla.mozilla.org/show_bug.cgi?id=858060https://bugzilla.mozilla.org/show_bug.cgi?id=861530https://bugzilla.mozilla.org/show_bug.cgi?id=862185https://bugzilla.mozilla.org/show_bug.cgi?id=870200https://bugzilla.mozilla.org/show_bug.cgi?id=874974https://bugzilla.mozilla.org/show_bug.cgi?id=878703https://bugzilla.mozilla.org/show_bug.cgi?id=879139https://bugzilla.mozilla.org/show_bug.cgi?id=893684https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18876
2013-08-07
Published