|
|
Log in / Subscribe / Register

mozilla: multiple vulnerabilities

Package(s):firefox thunderbird seamonkey CVE #(s):CVE-2013-0784 CVE-2013-0772 CVE-2013-0765 CVE-2013-0773 CVE-2013-0774 CVE-2013-0777 CVE-2013-0778 CVE-2013-0779 CVE-2013-0781
Created:February 20, 2013 Updated:June 3, 2013
Description: From the CVE entries:

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. (CVE-2013-0784)

The RasterImage::DrawFrameTo function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) via a crafted GIF image. (CVE-2013-0772)

Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 do not prevent multiple wrapping of WebIDL objects, which allows remote attackers to bypass intended access restrictions via unspecified vectors. (CVE-2013-0765)

The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent modifications to a prototype, which allows remote attackers to obtain sensitive information from chrome objects or possibly execute arbitrary JavaScript code with chrome privileges via a crafted web site. (CVE-2013-0773)

Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent JavaScript workers from reading the browser-profile directory name, which has unspecified impact and remote attack vectors. (CVE-2013-0774)

Use-after-free vulnerability in the nsDisplayBoxShadowOuter::Paint function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors. (CVE-2013-0777)

The ClusterIterator::NextCluster function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors. (CVE-2013-0778)

The nsCodingStateMachine::NextState function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors. (CVE-2013-0779)

Use-after-free vulnerability in the nsPrintEngine::CommonPrint function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors. (CVE-2013-0781)

Alerts:
openSUSE openSUSE-SU-2014:1100-1 Firefox 2014-09-09
Gentoo 201309-23 firefox 2013-09-27
Debian DSA-2699-1 iceweasel 2013-06-02
SUSE SUSE-SU-2013:0471-1 Mozilla Firefox 2013-03-15
Slackware SSA:2013-068-02 thunderbird 2013-03-09
Slackware SSA:2013-068-01 firefox 2013-03-09
Mageia MGASA-2013-0086 iceape 2013-03-09
SUSE SUSE-SU-2013:0410-1 Mozilla Firefox 2013-03-08
Ubuntu USN-1729-2 firefox 2013-02-28
Fedora FEDORA-2013-2988 seamonkey 2013-03-04
Fedora FEDORA-2013-2992 seamonkey 2013-03-04
Ubuntu USN-1748-1 thunderbird 2013-02-25
Slackware SSA:2013-056-01 seamonkey 2013-02-25
Fedora FEDORA-2013-2773 xulrunner 2013-02-23
Fedora FEDORA-2013-2794 xulrunner 2013-02-23
Fedora FEDORA-2013-2773 thunderbird 2013-02-23
Fedora FEDORA-2013-2794 thunderbird 2013-02-23
Fedora FEDORA-2013-2773 firefox 2013-02-23
Fedora FEDORA-2013-2794 firefox 2013-02-23
openSUSE openSUSE-SU-2013:0324-1 Mozilla 2013-02-22
openSUSE openSUSE-SU-2013:0323-1 Mozilla 2013-02-22
Mageia MGASA-2013-0065 thunderbird-lightning 2013-02-22
Mageia MGASA-2013-0064 thunderbird 2013-02-21
Mageia MGASA-2013-0063 firefox 2013-02-21
Ubuntu USN-1729-1 firefox 2013-02-19

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds