CVE-2013-0773

HIGH

Description

The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent modifications to a prototype, which allows remote attackers to obtain sensitive information from chrome objects or possibly execute arbitrary JavaScript code with chrome privileges via a crafted web site.

References

http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.html

http://lists.opensuse.org/opensuse-updates/2013-02/msg00062.html

http://www.debian.org/security/2013/dsa-2699

http://www.mozilla.org/security/announce/2013/mfsa2013-24.html

http://www.ubuntu.com/usn/USN-1729-1

http://www.ubuntu.com/usn/USN-1729-2

http://www.ubuntu.com/usn/USN-1748-1

https://bugzilla.mozilla.org/show_bug.cgi?id=809652

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16861

Details

Source: MITRE

Published: 2013-02-19

Updated: 2020-08-06

Risk Information

CVSS v2.0

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

Tenable Plugins

View all (24 total)

IDNameProductFamilySeverity
74898openSUSE Security Update : Mozilla (openSUSE-SU-2013:0323-1)NessusSuSE Local Security Checks
critical
70183GLSA-201309-23 : Mozilla Products: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
66766Debian DSA-2699-1 : iceweasel - several vulnerabilitiesNessusDebian Local Security Checks
critical
65598SuSE 10 Security Update : Mozilla Firefox (ZYPP Patch Number 8506)NessusSuSE Local Security Checks
critical
65175SuSE 11.2 Security Update : Mozilla Firefox (SAT Patch Number 7447)NessusSuSE Local Security Checks
critical
64967Ubuntu 11.10 / 12.04 LTS / 12.10 : firefox regression (USN-1729-2)NessusUbuntu Local Security Checks
critical
64892Ubuntu 10.04 LTS / 11.10 / 12.04 LTS / 12.10 : thunderbird vulnerabilities (USN-1748-1)NessusUbuntu Local Security Checks
critical
801258Mozilla SeaMonkey < 2.16 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
6693SeaMonkey < 2.16 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
801245Mozilla Thunderbird 17.x < 17.0.3 Multiple VulnerabilitiesLog Correlation EngineSMTP Clients
high
801233Mozilla Firefox 18.x <= 18 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
6692Mozilla Thunderbird < 17.0.3 Multiple VulnerabilitiesNessus Network MonitorSMTP Clients
high
6691Mozilla Firefox < 19.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
64726SeaMonkey < 2.16 Multiple VulnerabilitiesNessusWindows
critical
64725Mozilla Thunderbird ESR 17.x < 17.0.3 Multiple VulnerabilitiesNessusWindows
critical
64724Mozilla Thunderbird < 17.0.3 Multiple VulnerabilitiesNessusWindows
critical
64723Firefox < 19.0 Multiple VulnerabilitiesNessusWindows
critical
64722Firefox ESR 17.x < 17.0.3 Multiple VulnerabilitiesNessusWindows
critical
64721Thunderbird ESR 17.x < 17.0.3 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
64720Thunderbird < 17.0.3 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
64719Firefox 18.x Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
64718Firefox ESR 17.x < 17.0.3 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
64698Ubuntu 10.04 LTS / 11.10 / 12.04 LTS / 12.10 : firefox vulnerabilities (USN-1729-1)NessusUbuntu Local Security Checks
critical
64693FreeBSD : mozilla -- multiple vulnerabilities (e3f0374a-7ad6-11e2-84cd-d43d7e0c7c02)NessusFreeBSD Local Security Checks
high