|
|
Log in / Subscribe / Register

mozilla: multiple vulnerabilities

Package(s):firefox thunderbird seamonkey CVE #(s):CVE-2013-0775 CVE-2013-0776 CVE-2013-0780 CVE-2013-0782 CVE-2013-0783
Created:February 20, 2013 Updated:June 3, 2013
Description: From the CVE entries:

Use-after-free vulnerability in the nsImageLoadingContent::OnStopContainer function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code via crafted web script. (CVE-2013-0775)

Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow man-in-the-middle attackers to spoof the address bar by operating a proxy server that provides a 407 HTTP status code accompanied by web script, as demonstrated by a phishing attack on an HTTPS site. (CVE-2013-0776)

Use-after-free vulnerability in the nsOverflowContinuationTracker::Finish function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted document that uses Cascading Style Sheets (CSS) -moz-column-* properties. (CVE-2013-0780)

Heap-based buffer overflow in the nsSaveAsCharset::DoCharsetConversion function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code via unspecified vectors. (CVE-2013-0782)

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. (CVE-2013-0783)

Alerts:
openSUSE openSUSE-SU-2014:1100-1 Firefox 2014-09-09
Gentoo 201309-23 firefox 2013-09-27
Debian DSA-2699-1 iceweasel 2013-06-02
SUSE SUSE-SU-2013:0471-1 Mozilla Firefox 2013-03-15
Slackware SSA:2013-068-02 thunderbird 2013-03-09
Slackware SSA:2013-068-01 firefox 2013-03-09
Mageia MGASA-2013-0086 iceape 2013-03-09
SUSE SUSE-SU-2013:0410-1 Mozilla Firefox 2013-03-08
Ubuntu USN-1729-2 firefox 2013-02-28
Fedora FEDORA-2013-2988 seamonkey 2013-03-04
Fedora FEDORA-2013-2992 seamonkey 2013-03-04
Ubuntu USN-1748-1 thunderbird 2013-02-25
Slackware SSA:2013-056-01 seamonkey 2013-02-25
Fedora FEDORA-2013-2773 xulrunner 2013-02-23
Fedora FEDORA-2013-2794 xulrunner 2013-02-23
Fedora FEDORA-2013-2773 thunderbird 2013-02-23
Fedora FEDORA-2013-2794 thunderbird 2013-02-23
Fedora FEDORA-2013-2773 firefox 2013-02-23
Fedora FEDORA-2013-2794 firefox 2013-02-23
openSUSE openSUSE-SU-2013:0324-1 Mozilla 2013-02-22
openSUSE openSUSE-SU-2013:0323-1 Mozilla 2013-02-22
Mageia MGASA-2013-0065 thunderbird-lightning 2013-02-22
Mageia MGASA-2013-0064 thunderbird 2013-02-21
Mageia MGASA-2013-0063 firefox 2013-02-21
Oracle ELSA-2013-0271 firefox 2013-02-21
Oracle ELSA-2013-0271 firefox 2013-02-20
Oracle ELSA-2013-0272 thunderbird 2013-02-20
CentOS CESA-2013:0271 libproxy 2013-02-20
CentOS CESA-2013:0271 yelp 2013-02-20
CentOS CESA-2013:0271 xulrunner 2013-02-20
CentOS CESA-2013:0272 thunderbird 2013-02-20
CentOS CESA-2013:0271 firefox 2013-02-20
Scientific Linux SL-thun-20130220 thunderbird 2013-02-20
Scientific Linux SL-fire-20130220 firefox 2013-02-20
Ubuntu USN-1729-1 firefox 2013-02-19
Slackware SSA:2013-050-02 thunderbird 2013-02-19
Slackware SSA:2013-050-01 firefox 2013-02-19
CentOS CESA-2013:0272 thunderbird 2013-02-20
CentOS CESA-2013:0271 xulrunner 2013-02-20
CentOS CESA-2013:0271 devhelp 2013-02-20
CentOS CESA-2013:0271 yelp 2013-02-20
CentOS CESA-2013:0271 firefox 2013-02-20
Red Hat RHSA-2013:0272-01 thunderbird 2013-02-19
Red Hat RHSA-2013:0271-01 firefox 2013-02-19

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds