CVE-2013-5612
published 2013-12-11CVE-2013-5612: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.40%
87.6th percentile
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging a Same Origin Policy violation triggered by lack of a charset parameter in a Content-Type HTTP header.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mozilla | firefox | < 26.0 | 26.0 |
| mozilla | seamonkey | < 2.23 | 2.23 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu9.8CRITICAL
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-12-11·CVSS 9.8
CVE-2013-5609 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Ben Turner, Bobby Holley, Jesse Ruderman, Christian Holler and Christoph
Diehl discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2013-5609, CVE-2013-5610)
Myk Melez discovered that the doorhanger notification for web app
installation could persist between page navigations. An attacker could
potentially exploit this to conduct clickjacking attacks. (CVE-2013-5611)
Masato Kinugawa discovered that pages with missin
Red Hat
Mozilla: Character encoding cross-origin XSS attack (MFSA 2013-106)
vendor_redhat·2013-12-10·CVSS 4.3
CVE-2013-5612 [MEDIUM] CWE-79 Mozilla: Character encoding cross-origin XSS attack (MFSA 2013-106)
Mozilla: Character encoding cross-origin XSS attack (MFSA 2013-106)
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging a Same Origin Policy violation triggered by lack of a charset parameter in a Content-Type HTTP header.
GHSA
GHSA-f85h-xqx2-v9xg: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26
ghsa_unreviewed·2022-05-13
CVE-2013-5612 [MEDIUM] CWE-79 GHSA-f85h-xqx2-v9xg: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging a Same Origin Policy violation triggered by lack of a charset parameter in a Content-Type HTTP header.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-5612 Mozilla: Character encoding cross-origin XSS attack (MFSA 2013-106)
bugzilla·2013-12-09·CVSS 4.3
CVE-2013-5612 [MEDIUM] CVE-2013-5612 Mozilla: Character encoding cross-origin XSS attack (MFSA 2013-106)
CVE-2013-5612 Mozilla: Character encoding cross-origin XSS attack (MFSA 2013-106)
Security researcher Masato Kinugawa discovered that if a web page is missing character set encoding information it can inherit character encodings across navigations into another domain from an earlier site. Only same-origin inheritance is allowed according to the HTML5 specification. This issue allows an attacker to add content that will be interpreted one way on the victim site, but which may then behave differently, evading cross-site scripting (XSS) filtering, when forced into an unexpected character set. Web site authors should always explicitly declare a character encoding to avoid similar issues.
In general these flaws cannot be exploited through email in the Thunderbird and Seamonkey products becaus
Bugzilla
mysql: Oracle CPU January 2013
bugzilla·2013-01-15·CVSS 6.5
CVE-2012-5611 [MEDIUM] mysql: Oracle CPU January 2013
mysql: Oracle CPU January 2013
This bug is for Oracle Critical Patch Update Advisory - January 2013:
http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Pre-release of the advisory indicates that it will include 18 CVEs for MySQL, 2 of them remotely exploitable without authentication.
This update is likely to mention previously published issues as CVE-2012-5611 (bug 881064, comment 21) and CVE-2012-5612 (bug 882600).
Discussion:
MySQL risk matrix:
http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html#AppendixMSQL
Fixes are included in version 5.1.67 and 5.5.29.
Previous CPU for MySQL was released in October 2012 (bug 870399) and covered issues up to versions 5.1.66 and 5.5.28. Hence these are releases since the last CPU:
http://dev.mysql.c
http://lists.fedoraproject.org/pipermail/package-announce/2013-December/123437.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-December/124257.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-12/msg00010.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00085.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00086.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00087.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1812.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-106.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/64205http://www.securitytracker.com/id/1029470http://www.securitytracker.com/id/1029476http://www.ubuntu.com/usn/USN-2052-1https://bugzilla.mozilla.org/show_bug.cgi?id=871161https://security.gentoo.org/glsa/201504-01http://lists.fedoraproject.org/pipermail/package-announce/2013-December/123437.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-December/124257.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-12/msg00010.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00085.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00086.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00087.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1812.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-106.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/64205http://www.securitytracker.com/id/1029470http://www.securitytracker.com/id/1029476http://www.ubuntu.com/usn/USN-2052-1https://bugzilla.mozilla.org/show_bug.cgi?id=871161https://security.gentoo.org/glsa/201504-01
2013-12-11
Published