CVE-2013-5592
published 2013-10-30CVE-2013-5592: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 25.0 allow remote attackers to cause a denial of service (memory…
PriorityP338critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.10%
91.5th percentile
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 25.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 24.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vgj8-9328-h497: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 25
ghsa_unreviewed·2022-05-17
CVE-2013-5592 [HIGH] GHSA-vgj8-9328-h497: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 25
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 25.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-10-29·CVSS 5.0
CVE-2013-1739 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple memory safety issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute arbitrary code with the privileges of the user
invoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,
CVE-2013-5592)
Jordi Chancel discovered that HTML select elements could display arbitrary
content. An attacker could potentially exploit this to conduct
URL spoofing or clickjacking attacks (CVE-2013-5593)
Abhishek Arya discovered a crash when processing XSLT data in some
circumstances. An attacker could potenti
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00006.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-93.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=880544https://bugzilla.mozilla.org/show_bug.cgi?id=886102https://bugzilla.mozilla.org/show_bug.cgi?id=887921https://bugzilla.mozilla.org/show_bug.cgi?id=912534https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19148https://security.gentoo.org/glsa/201504-01http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00006.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-93.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=880544https://bugzilla.mozilla.org/show_bug.cgi?id=886102https://bugzilla.mozilla.org/show_bug.cgi?id=887921https://bugzilla.mozilla.org/show_bug.cgi?id=912534https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19148https://security.gentoo.org/glsa/201504-01
2013-10-30
Published