CVE-2013-1690

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html Mailing List Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0981.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0982.html Third Party Advisory
http://www.debian.org/security/2013/dsa-2716 Mailing List Third Party Advisory
http://www.debian.org/security/2013/dsa-2720 Mailing List Third Party Advisory
http://www.mozilla.org/security/announce/2013/mfsa2013-53.html Vendor Advisory
http://www.securityfocus.com/bid/60778 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-1890-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-1891-1 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=857883 Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=901365 Issue Tracking
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996 Broken Link
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html Mailing List Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0981.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0982.html Third Party Advisory
http://www.debian.org/security/2013/dsa-2716 Mailing List Third Party Advisory
http://www.debian.org/security/2013/dsa-2720 Mailing List Third Party Advisory
http://www.mozilla.org/security/announce/2013/mfsa2013-53.html Vendor Advisory
http://www.securityfocus.com/bid/60778 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-1890-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-1891-1 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=857883 Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=901365 Issue Tracking
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996 Broken Link
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:redhat:gluster_storage_server_for_on-premise:2.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:5.9:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:6.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:5.9:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:10:sp4:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp2:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:ltss:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:ltss:vmware:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:vmware:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp3:*:*:*:*:*:*

History

21 Nov 2024, 01:50

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html - Mailing List, Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2013-0981.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2013-0981.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2013-0982.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2013-0982.html - Third Party Advisory
References () http://www.debian.org/security/2013/dsa-2716 - Mailing List, Third Party Advisory () http://www.debian.org/security/2013/dsa-2716 - Mailing List, Third Party Advisory
References () http://www.debian.org/security/2013/dsa-2720 - Mailing List, Third Party Advisory () http://www.debian.org/security/2013/dsa-2720 - Mailing List, Third Party Advisory
References () http://www.mozilla.org/security/announce/2013/mfsa2013-53.html - Vendor Advisory () http://www.mozilla.org/security/announce/2013/mfsa2013-53.html - Vendor Advisory
References () http://www.securityfocus.com/bid/60778 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/60778 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.ubuntu.com/usn/USN-1890-1 - Third Party Advisory () http://www.ubuntu.com/usn/USN-1890-1 - Third Party Advisory
References () http://www.ubuntu.com/usn/USN-1891-1 - Third Party Advisory () http://www.ubuntu.com/usn/USN-1891-1 - Third Party Advisory
References () https://bugzilla.mozilla.org/show_bug.cgi?id=857883 - Issue Tracking () https://bugzilla.mozilla.org/show_bug.cgi?id=857883 - Issue Tracking
References () https://bugzilla.mozilla.org/show_bug.cgi?id=901365 - Issue Tracking () https://bugzilla.mozilla.org/show_bug.cgi?id=901365 - Issue Tracking
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996 - Broken Link () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996 - Broken Link

21 Oct 2024, 13:55

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*

09 Jul 2024, 18:25

Type Values Removed Values Added
First Time Suse linux Enterprise Desktop
Redhat enterprise Linux Workstation
Suse
Suse linux Enterprise Software Development Kit
Opensuse opensuse
Debian
Redhat
Suse linux Enterprise Server
Redhat gluster Storage Server For On-premise
Redhat enterprise Linux Eus
Canonical ubuntu Linux
Opensuse
Redhat enterprise Linux Desktop
Canonical
Debian debian Linux
Redhat enterprise Linux Server
Redhat enterprise Linux Server Aus
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html - () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html - () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html - () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html - () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html - () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html - () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html - Mailing List, Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2013-0981.html - () http://rhn.redhat.com/errata/RHSA-2013-0981.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2013-0982.html - () http://rhn.redhat.com/errata/RHSA-2013-0982.html - Third Party Advisory
References () http://www.debian.org/security/2013/dsa-2716 - () http://www.debian.org/security/2013/dsa-2716 - Mailing List, Third Party Advisory
References () http://www.debian.org/security/2013/dsa-2720 - () http://www.debian.org/security/2013/dsa-2720 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/60778 - () http://www.securityfocus.com/bid/60778 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.ubuntu.com/usn/USN-1890-1 - () http://www.ubuntu.com/usn/USN-1890-1 - Third Party Advisory
References () http://www.ubuntu.com/usn/USN-1891-1 - () http://www.ubuntu.com/usn/USN-1891-1 - Third Party Advisory
References () https://bugzilla.mozilla.org/show_bug.cgi?id=857883 - () https://bugzilla.mozilla.org/show_bug.cgi?id=857883 - Issue Tracking
References () https://bugzilla.mozilla.org/show_bug.cgi?id=901365 - () https://bugzilla.mozilla.org/show_bug.cgi?id=901365 - Issue Tracking
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996 - Broken Link
CVSS v2 : 9.3
v3 : unknown
v2 : 9.3
v3 : 8.8
CPE cpe:2.3:a:mozilla:thunderbird:17.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:19.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:20.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:19.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:19.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:20.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:-:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:10:sp4:*:*:-:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:5.9:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp3:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:5.9:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:vmware:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:ltss:-:*:*
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:ltss:vmware:*:*
cpe:2.3:a:mozilla:thunderbird_esr:*:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp2:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:-:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:6.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:gluster_storage_server_for_on-premise:2.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:-:*:*

Information

Published : 2013-06-26 03:19

Updated : 2024-11-21 01:50


NVD link : CVE-2013-1690

Mitre link : CVE-2013-1690

CVE.ORG link : CVE-2013-1690


JSON object : View

Products Affected

mozilla

  • firefox
  • thunderbird
  • thunderbird_esr

redhat

  • enterprise_linux_server
  • enterprise_linux_desktop
  • enterprise_linux_server_aus
  • enterprise_linux_eus
  • enterprise_linux_workstation
  • gluster_storage_server_for_on-premise

opensuse

  • opensuse

suse

  • linux_enterprise_software_development_kit
  • linux_enterprise_server
  • linux_enterprise_desktop

canonical

  • ubuntu_linux

debian

  • debian_linux
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer