CVE-2013-1714
published 2013-08-07CVE-2013-1714: The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.09%
79.5th percentile
The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 does not properly restrict XMLHttpRequest calls, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via unspecified vectors.
Affected
84 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 22.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 2.20 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu10.0CRITICAL
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p7q2-jcwm-cgcm: The Web Workers implementation in Mozilla Firefox before 23
ghsa_unreviewed·2022-05-17
CVE-2013-1714 [MEDIUM] GHSA-p7q2-jcwm-cgcm: The Web Workers implementation in Mozilla Firefox before 23
The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 does not properly restrict XMLHttpRequest calls, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via unspecified vectors.
Red Hat
Mozilla: Same-origin bypass with web workers and XMLHttpRequest (MFSA 2013-73)
vendor_redhat·2013-08-07·CVSS 4.3
CVE-2013-1714 [MEDIUM] Mozilla: Same-origin bypass with web workers and XMLHttpRequest (MFSA 2013-73)
Mozilla: Same-origin bypass with web workers and XMLHttpRequest (MFSA 2013-73)
The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 does not properly restrict XMLHttpRequest calls, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via unspecified vectors.
Package: thunderbird (Red Hat Enterprise Linux 5) - Affected
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2013-08-07·CVSS 10.0
CVE-2013-1701 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Jeff Gilbert and Henrik Skupin discovered multiple memory safety issues
in Thunderbird. If the user were tricked in to opening a specially crafted
message with scripting enabled, an attacker could possibly exploit these
to cause a denial of service via application crash, or potentially execute
arbitrary code with the privileges of the user invoking Thunderbird.
(CVE-2013-1701)
It was discovered that a document's URI could be set to the URI of
a different document. If a user had scripting enabled, an attacker
could potentially exploit this to conduct cross-site scripting (XSS)
attacks. (CVE-2013-1709)
A flaw was discovered when generating a CRMF request in certain
circumstances. If a user had
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-08-06·CVSS 10.0
CVE-2013-1701 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Jeff Gilbert, Henrik Skupin, Ben Turner, Christian Holler,
Andrew McCreight, Gary Kwong, Jan Varga and Jesse Ruderman discovered
multiple memory safety issues in Firefox. If the user were tricked in to
opening a specially crafted page, an attacker could possibly exploit these
to cause a denial of service via application crash, or potentially execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1701, CVE-2013-1702)
A use-after-free bug was discovered when the DOM is modified during a
SetBody mutation event. If the user were tricked in to opening a specially
crafted page, an attacker could potentially exploit this to execute
a
Ubuntu
Ubufox and Unity Firefox Extension update
vendor_ubuntu·2013-08-06·CVSS 10.0
[CRITICAL] Ubufox and Unity Firefox Extension update
Title: Ubufox and Unity Firefox Extension update
Summary: This update provides compatible packages for Firefox 23.
USN-1924-1 fixed vulnerabilities in Firefox. This update provides the
corresponding updates for Ubufox and Unity Firefox Extension.
Original advisory details:
Jeff Gilbert, Henrik Skupin, Ben Turner, Christian Holler,
Andrew McCreight, Gary Kwong, Jan Varga and Jesse Ruderman discovered
multiple memory safety issues in Firefox. If the user were tricked in to
opening a specially crafted page, an attacker could possibly exploit these
to cause a denial of service via application crash, or potentially execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1701, CVE-2013-1702)
A use-after-free bug was discovered when the DOM is modified during a
Set
No detection rules found.
No public exploits indexed.
http://www.debian.org/security/2013/dsa-2735http://www.debian.org/security/2013/dsa-2746http://www.mozilla.org/security/announce/2013/mfsa2013-73.htmlhttp://www.securityfocus.com/bid/61882https://bugzilla.mozilla.org/show_bug.cgi?id=879787https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18002http://www.debian.org/security/2013/dsa-2735http://www.debian.org/security/2013/dsa-2746http://www.mozilla.org/security/announce/2013/mfsa2013-73.htmlhttp://www.securityfocus.com/bid/61882https://bugzilla.mozilla.org/show_bug.cgi?id=879787https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18002
2013-08-07
Published