CVE-2013-1719
published 2013-09-18CVE-2013-1719: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allow remote…
PriorityP339critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.44%
91.8th percentile
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 23.0.1 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 2.20 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Miscellaneous memory safety hazards (rv:24.0) (MFSA 2013-76)
vendor_redhat·2013-09-17·CVSS 10.0
CVE-2013-1719 [CRITICAL] Mozilla: Miscellaneous memory safety hazards (rv:24.0) (MFSA 2013-76)
Mozilla: Miscellaneous memory safety hazards (rv:24.0) (MFSA 2013-76)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-09-17·CVSS 10.0
CVE-2013-1718 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple memory safety issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute arbitrary code with the privileges of the user
invoking Firefox. (CVE-2013-1718, CVE-2013-1719)
Atte Kettunen discovered a flaw in the HTML5 Tree Builder when interacting
with template elements. In some circumstances, an attacker could
potentially exploit this to execute arbitrary code with the privileges of
the user invoking Firefox. (CVE-2013-1720)
Alex Chapman discovered an integer overflow vulnerability in the ANGLE
GHSA
GHSA-823h-7w9q-9gj3: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24
ghsa_unreviewed·2022-05-17
CVE-2013-1719 [HIGH] CWE-119 GHSA-823h-7w9q-9gj3: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115907.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-September/116610.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-September/117526.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00055.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00057.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00059.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00061.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-76.htmlhttp://www.securityfocus.com/bid/62462http://www.ubuntu.com/usn/USN-1951-1https://bugzilla.mozilla.org/show_bug.cgi?id=750932https://bugzilla.mozilla.org/show_bug.cgi?id=847606https://bugzilla.mozilla.org/show_bug.cgi?id=851982https://bugzilla.mozilla.org/show_bug.cgi?id=854897https://bugzilla.mozilla.org/show_bug.cgi?id=863935https://bugzilla.mozilla.org/show_bug.cgi?id=871462https://bugzilla.mozilla.org/show_bug.cgi?id=873073https://bugzilla.mozilla.org/show_bug.cgi?id=876878https://bugzilla.mozilla.org/show_bug.cgi?id=883450https://bugzilla.mozilla.org/show_bug.cgi?id=893519https://bugzilla.mozilla.org/show_bug.cgi?id=895294https://bugzilla.mozilla.org/show_bug.cgi?id=896126https://bugzilla.mozilla.org/show_bug.cgi?id=898381https://bugzilla.mozilla.org/show_bug.cgi?id=898832https://bugzilla.mozilla.org/show_bug.cgi?id=909494https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19011http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115907.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-September/116610.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-September/117526.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00055.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00057.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00059.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00061.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-76.htmlhttp://www.securityfocus.com/bid/62462http://www.ubuntu.com/usn/USN-1951-1https://bugzilla.mozilla.org/show_bug.cgi?id=750932https://bugzilla.mozilla.org/show_bug.cgi?id=847606https://bugzilla.mozilla.org/show_bug.cgi?id=851982https://bugzilla.mozilla.org/show_bug.cgi?id=854897https://bugzilla.mozilla.org/show_bug.cgi?id=863935https://bugzilla.mozilla.org/show_bug.cgi?id=871462https://bugzilla.mozilla.org/show_bug.cgi?id=873073https://bugzilla.mozilla.org/show_bug.cgi?id=876878https://bugzilla.mozilla.org/show_bug.cgi?id=883450https://bugzilla.mozilla.org/show_bug.cgi?id=893519https://bugzilla.mozilla.org/show_bug.cgi?id=895294https://bugzilla.mozilla.org/show_bug.cgi?id=896126https://bugzilla.mozilla.org/show_bug.cgi?id=898381https://bugzilla.mozilla.org/show_bug.cgi?id=898832https://bugzilla.mozilla.org/show_bug.cgi?id=909494https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19011
2013-09-18
Published