CVE-2013-1690

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html Mailing List Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0981.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0982.html Third Party Advisory
http://www.debian.org/security/2013/dsa-2716 Mailing List Third Party Advisory
http://www.debian.org/security/2013/dsa-2720 Mailing List Third Party Advisory
http://www.mozilla.org/security/announce/2013/mfsa2013-53.html Vendor Advisory
http://www.securityfocus.com/bid/60778 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-1890-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-1891-1 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=857883 Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=901365 Issue Tracking
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996 Broken Link
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html Mailing List Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0981.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0982.html Third Party Advisory
http://www.debian.org/security/2013/dsa-2716 Mailing List Third Party Advisory
http://www.debian.org/security/2013/dsa-2720 Mailing List Third Party Advisory
http://www.mozilla.org/security/announce/2013/mfsa2013-53.html Vendor Advisory
http://www.securityfocus.com/bid/60778 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-1890-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-1891-1 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=857883 Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=901365 Issue Tracking
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996 Broken Link
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:redhat:gluster_storage_server_for_on-premise:2.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:5.9:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:6.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:5.9:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:10:sp4:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp2:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:ltss:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:ltss:vmware:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:vmware:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp4:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp3:*:*:*:*:*:*

History

21 Nov 2024, 01:50

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html - Mailing List, Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2013-0981.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2013-0981.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2013-0982.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2013-0982.html - Third Party Advisory
References () http://www.debian.org/security/2013/dsa-2716 - Mailing List, Third Party Advisory () http://www.debian.org/security/2013/dsa-2716 - Mailing List, Third Party Advisory
References () http://www.debian.org/security/2013/dsa-2720 - Mailing List, Third Party Advisory () http://www.debian.org/security/2013/dsa-2720 - Mailing List, Third Party Advisory
References () http://www.mozilla.org/security/announce/2013/mfsa2013-53.html - Vendor Advisory () http://www.mozilla.org/security/announce/2013/mfsa2013-53.html - Vendor Advisory
References () http://www.securityfocus.com/bid/60778 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/60778 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.ubuntu.com/usn/USN-1890-1 - Third Party Advisory () http://www.ubuntu.com/usn/USN-1890-1 - Third Party Advisory
References () http://www.ubuntu.com/usn/USN-1891-1 - Third Party Advisory () http://www.ubuntu.com/usn/USN-1891-1 - Third Party Advisory
References () https://bugzilla.mozilla.org/show_bug.cgi?id=857883 - Issue Tracking () https://bugzilla.mozilla.org/show_bug.cgi?id=857883 - Issue Tracking
References () https://bugzilla.mozilla.org/show_bug.cgi?id=901365 - Issue Tracking () https://bugzilla.mozilla.org/show_bug.cgi?id=901365 - Issue Tracking
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996 - Broken Link () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996 - Broken Link

21 Oct 2024, 13:55

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*

09 Jul 2024, 18:25

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:thunderbird:17.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:20.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:19.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:19.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:20.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:19.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.3:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:5.9:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.4:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:vmware:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:6.4:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:-:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:ltss:vmware:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:gluster_storage_server_for_on-premise:2.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:10:sp4:*:*:-:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:5.9:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:*
cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp4:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:-:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp3:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp2:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:ltss:-:*:*
CVSS v2 : 9.3
v3 : unknown
v2 : 9.3
v3 : 8.8
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html - () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html - () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html - () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html - () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html - () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html - () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html - Mailing List, Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2013-0981.html - () http://rhn.redhat.com/errata/RHSA-2013-0981.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2013-0982.html - () http://rhn.redhat.com/errata/RHSA-2013-0982.html - Third Party Advisory
References () http://www.debian.org/security/2013/dsa-2716 - () http://www.debian.org/security/2013/dsa-2716 - Mailing List, Third Party Advisory
References () http://www.debian.org/security/2013/dsa-2720 - () http://www.debian.org/security/2013/dsa-2720 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/60778 - () http://www.securityfocus.com/bid/60778 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.ubuntu.com/usn/USN-1890-1 - () http://www.ubuntu.com/usn/USN-1890-1 - Third Party Advisory
References () http://www.ubuntu.com/usn/USN-1891-1 - () http://www.ubuntu.com/usn/USN-1891-1 - Third Party Advisory
References () https://bugzilla.mozilla.org/show_bug.cgi?id=857883 - () https://bugzilla.mozilla.org/show_bug.cgi?id=857883 - Issue Tracking
References () https://bugzilla.mozilla.org/show_bug.cgi?id=901365 - () https://bugzilla.mozilla.org/show_bug.cgi?id=901365 - Issue Tracking
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996 - Broken Link
First Time Suse linux Enterprise Server
Redhat enterprise Linux Eus
Suse linux Enterprise Software Development Kit
Redhat enterprise Linux Server
Redhat enterprise Linux Desktop
Redhat
Suse
Opensuse opensuse
Canonical
Redhat enterprise Linux Server Aus
Opensuse
Suse linux Enterprise Desktop
Redhat gluster Storage Server For On-premise
Redhat enterprise Linux Workstation
Canonical ubuntu Linux
Debian debian Linux
Debian

Information

Published : 2013-06-26 03:19

Updated : 2025-04-11 00:51


NVD link : CVE-2013-1690

Mitre link : CVE-2013-1690

CVE.ORG link : CVE-2013-1690


JSON object : View

Products Affected

redhat

  • enterprise_linux_workstation
  • enterprise_linux_desktop
  • enterprise_linux_server_aus
  • enterprise_linux_eus
  • gluster_storage_server_for_on-premise
  • enterprise_linux_server

mozilla

  • thunderbird
  • thunderbird_esr
  • firefox

suse

  • linux_enterprise_desktop
  • linux_enterprise_software_development_kit
  • linux_enterprise_server

debian

  • debian_linux

opensuse

  • opensuse

canonical

  • ubuntu_linux
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer