Vulnerability Name:

CVE-2013-0784 (CCN-82182)

Assigned:2013-02-19
Published:2013-02-19
Updated:2020-08-06
Summary:Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2013-0784

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2013:0323

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2013:0324

Source: CCN
Type: SA52249
Mozilla Firefox Multiple Vulnerabilities

Source: CCN
Type: SA52280
Mozilla Thunderbird / SeaMonkey Multiple Vulnerabilities

Source: CCN
Type: SA52286
Mozilla Firefox ESR Multiple Vulnerabilities

Source: CONFIRM
Type: Vendor Advisory
http://www.mozilla.org/security/announce/2013/mfsa2013-21.html

Source: CCN
Type: BID-58040
Mozilla Firefox/Thunderbird/SeaMonkey CVE-2013-0784 Memory Corruption Vulnerability

Source: UBUNTU
Type: Third Party Advisory
USN-1729-1

Source: UBUNTU
Type: Third Party Advisory
USN-1729-2

Source: UBUNTU
Type: Third Party Advisory
USN-1748-1

Source: CONFIRM
Type: Issue Tracking, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=766452

Source: CONFIRM
Type: Issue Tracking, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=790373

Source: CONFIRM
Type: Issue Tracking, Patch, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=797977

Source: CONFIRM
Type: Exploit, Issue Tracking, Patch, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=799803

Source: CONFIRM
Type: Exploit, Issue Tracking, Patch, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=799907

Source: CONFIRM
Type: Issue Tracking, Patch, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=801114

Source: CONFIRM
Type: Issue Tracking, Patch, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=805294

Source: CONFIRM
Type: Issue Tracking, Patch, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=809295

Source: CONFIRM
Type: Issue Tracking, Patch, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=810169

Source: CONFIRM
Type: Exploit, Issue Tracking, Patch, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=819635

Source: CONFIRM
Type: Issue Tracking, Patch, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=827687

Source: CONFIRM
Type: Issue Tracking, Patch, Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=830943

Source: XF
Type: UNKNOWN
mozilla-cve20130784-code-exec(82182)

Source: OVAL
Type: Third Party Advisory
oval:org.mitre.oval:def:17119

Source: CCN
Type: MFSA 2013-21
Miscellaneous memory safety hazards

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2013-0784

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mozilla:firefox:*:*:*:*:*:*:*:* (Version < 19.0)
  • OR cpe:/a:mozilla:firefox_esr:*:*:*:*:*:*:*:* (Version < 17.0.3)
  • OR cpe:/a:mozilla:seamonkey:*:*:*:*:*:*:*:* (Version < 2.16)
  • OR cpe:/a:mozilla:thunderbird:*:*:*:*:*:*:*:* (Version < 17.0.3)
  • OR cpe:/a:mozilla:thunderbird_esr:*:*:*:*:*:*:*:* (Version < 17.0.3)

  • Configuration 2:
  • cpe:/o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:12.2:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:mozilla:firefox:18.0:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox_esr:17.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:thunderbird:17.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:thunderbird_esr:17.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:seamonkey:2.15:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:17119
    V
    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
    2014-10-06
    oval:org.mitre.oval:def:18309
    P
    USN-1748-1 -- thunderbird vulnerabilities
    2014-07-21
    oval:org.mitre.oval:def:17832
    P
    USN-1729-2 -- firefox regression
    2014-07-07
    oval:org.mitre.oval:def:18301
    P
    USN-1729-1 -- firefox vulnerabilities
    2014-06-30
    oval:com.ubuntu.precise:def:20130784000
    V
    CVE-2013-0784 on Ubuntu 12.04 LTS (precise) - medium.
    2013-02-19
    BACK
    mozilla firefox *
    mozilla firefox esr *
    mozilla seamonkey *
    mozilla thunderbird *
    mozilla thunderbird esr *
    opensuse opensuse 11.4
    opensuse opensuse 12.1
    opensuse opensuse 12.2
    canonical ubuntu linux 10.04
    canonical ubuntu linux 11.10
    canonical ubuntu linux 12.04
    canonical ubuntu linux 12.10
    mozilla firefox 18.0
    mozilla firefox esr 17.0.2
    mozilla thunderbird 17.0.2
    mozilla thunderbird esr 17.0.2
    mozilla seamonkey 2.15