CVE-2013-5619
published 2013-12-11CVE-2013-5619: Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote…
PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.71%
88.5th percentile
Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JavaScript code.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mozilla | firefox | < 26.0 | 26.0 |
| mozilla | seamonkey | < 2.23 | 2.23 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_ubuntu9.8CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-12-11·CVSS 9.8
CVE-2013-5609 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Ben Turner, Bobby Holley, Jesse Ruderman, Christian Holler and Christoph
Diehl discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2013-5609, CVE-2013-5610)
Myk Melez discovered that the doorhanger notification for web app
installation could persist between page navigations. An attacker could
potentially exploit this to conduct clickjacking attacks. (CVE-2013-5611)
Masato Kinugawa discovered that pages with missin
Red Hat
Mozilla: Potential overflow in JavaScript binary search algorithms (MFSA 2013-110)
vendor_redhat·2013-12-10·CVSS 7.5
CVE-2013-5619 [HIGH] Mozilla: Potential overflow in JavaScript binary search algorithms (MFSA 2013-110)
Mozilla: Potential overflow in JavaScript binary search algorithms (MFSA 2013-110)
Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JavaScript code.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-cjg8-q3v9-46r8: Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26
ghsa_unreviewed·2022-05-13
CVE-2013-5619 [HIGH] CWE-190 GHSA-cjg8-q3v9-46r8: Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26
Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JavaScript code.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2013-December/123437.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-December/124257.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-12/msg00010.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00085.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00086.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00087.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00002.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-110.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securitytracker.com/id/1029470http://www.securitytracker.com/id/1029476http://www.ubuntu.com/usn/USN-2052-1https://bugzilla.mozilla.org/show_bug.cgi?id=917841https://security.gentoo.org/glsa/201504-01http://lists.fedoraproject.org/pipermail/package-announce/2013-December/123437.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-December/124257.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-12/msg00010.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00085.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00086.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00087.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00002.htmlhttp://www.mozilla.org/security/announce/2013/mfsa2013-110.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securitytracker.com/id/1029470http://www.securitytracker.com/id/1029476http://www.ubuntu.com/usn/USN-2052-1https://bugzilla.mozilla.org/show_bug.cgi?id=917841https://security.gentoo.org/glsa/201504-01
2013-12-11
Published