CVE-2013-0749
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.80%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 5.80% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird · mozilla/thunderbird esr · opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · canonical/ubuntu linux
- Source
- security@mozilla.org
References
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00007.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00010.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00017.htmlMailing List, Third Party Advisory
- http://www.mozilla.org/security/announce/2013/mfsa2013-01.htmlVendor Advisory
- http://www.palemoon.org/releasenotes-ng.shtmlBroken Link
- http://www.ubuntu.com/usn/USN-1681-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-1681-2Third Party Advisory
- http://www.ubuntu.com/usn/USN-1681-4Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=785358Issue Tracking, Patch, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=794426Issue Tracking, Patch, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=805745Exploit, Issue Tracking, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=805814Exploit, Issue Tracking, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=808481Issue Tracking, Patch, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=812847Issue Tracking, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=814407Issue Tracking, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=814839Issue Tracking, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=816994Issue Tracking, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16953Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00007.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00010.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00017.htmlMailing List, Third Party Advisory
- http://www.mozilla.org/security/announce/2013/mfsa2013-01.htmlVendor Advisory
- http://www.palemoon.org/releasenotes-ng.shtmlBroken Link
- http://www.ubuntu.com/usn/USN-1681-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-1681-2Third Party Advisory
- http://www.ubuntu.com/usn/USN-1681-4Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=785358Issue Tracking, Patch, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=794426Issue Tracking, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.