MEDIUM
Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly restrict local-filesystem access by Java applets, which allows user-assisted remote attackers to read arbitrary files by leveraging a download to a fixed pathname or other predictable pathname.
http://www.debian.org/security/2013/dsa-2735
http://www.debian.org/security/2013/dsa-2746
http://www.mozilla.org/security/announce/2013/mfsa2013-75.html
http://www.securityfocus.com/bid/61896
https://bugzilla.mozilla.org/show_bug.cgi?id=406541
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18367
OR
cpe:2.3:a:mozilla:thunderbird_esr:17.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird_esr:17.0.5:*:*:*:*:*:*:*
OR
cpe:2.3:a:mozilla:firefox:19.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:19.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:19.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:20.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:20.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:21.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* versions up to 22.0 (inclusive)
OR
cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:beta_1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:beta_2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.9:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.10:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.11:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.12:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.13:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.14:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.1:alpha1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.1:alpha2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.1:alpha3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.1:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.1:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.1:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.1:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.1:rc2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.2:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.2:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.2:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.3:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.3:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.3:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.3.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.3.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.4:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.4:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.4:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.5:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.5:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.5:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.5:beta4:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.6:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.6:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.6:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.6:beta4:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.6.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.7:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.7:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.7:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.7:beta4:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.7:beta5:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.7.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.8:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.8:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.8:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.8:beta4:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.8:beta5:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.8:beta6:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.9:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.9:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.9:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.9:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.9:beta4:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.9.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.10:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.10:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.10:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.10:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.10.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.11:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.11:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.11:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.11:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.11:beta4:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.11:beta5:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.11:beta6:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.12:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.12:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.12:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.12:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.12:beta4:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.12:beta5:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.12:beta6:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.12.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.13:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.13:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.13:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.13:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.13:beta4:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.13:beta5:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.13:beta6:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.13.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.13.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.14:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.14:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.14:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.14:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.14:beta4:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.14:beta5:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.15:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.15:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.15:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.15:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.15:beta4:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.15:beta5:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.15:beta6:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.15.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.15.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.16:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.16:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.16:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.16:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.16:beta4:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.16:beta5:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.16.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.16.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.17:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.17:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.17:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.17:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.17:beta4:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.17.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.18:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.18:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.18:beta3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.18:beta4:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.19:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.19:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.19:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.20:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.20:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:*:beta3:*:*:*:*:*:* versions up to 2.20 (inclusive)
OR
cpe:2.3:a:mozilla:firefox_esr:17.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:17.0.5:*:*:*:*:*:*:*
OR
cpe:2.3:a:mozilla:thunderbird:17.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:17.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* versions up to 17.0.7 (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
75122 | openSUSE Security Update : MozillaFirefox / MozillaThunderbird / mozilla-nspr / etc (openSUSE-SU-2013:1348-1) | Nessus | SuSE Local Security Checks | critical |
70183 | GLSA-201309-23 : Mozilla Products: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | critical |
69506 | Debian DSA-2746-1 : icedove - several vulnerabilities | Nessus | Debian Local Security Checks | critical |
69344 | SuSE 11.2 / 11.3 Security Update : Mozilla Firefox (SAT Patch Numbers 8187 / 8191) | Nessus | SuSE Local Security Checks | critical |
69343 | SuSE 11.2 / 11.3 Security Update : Mozilla Firefox (SAT Patch Numbers 8187 / 8191) | Nessus | SuSE Local Security Checks | critical |
69278 | FreeBSD : mozilla -- multiple vulnerabilities (0998e79d-0055-11e3-905b-0025905a4771) | Nessus | FreeBSD Local Security Checks | critical |
69277 | Debian DSA-2735-1 : iceweasel - several vulnerabilities | Nessus | Debian Local Security Checks | critical |
801464 | Mozilla Thunderbird < 17.0.8 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | medium |
801463 | Mozilla Firefox < 23.0 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | medium |
801462 | Mozilla SeaMonkey < 2.20 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | medium |
69272 | SeaMonkey < 2.20 Multiple Vulnerabilities | Nessus | Windows | critical |
69271 | Mozilla Thunderbird ESR 17.x < 17.0.8 Multiple Vulnerabilities | Nessus | Windows | critical |
69270 | Mozilla Thunderbird < 17.0.8 Multiple Vulnerabilities | Nessus | Windows | critical |
69269 | Firefox < 23.0 Multiple Vulnerabilities | Nessus | Windows | critical |
69268 | Firefox ESR 17.x < 17.0.8 Multiple Vulnerabilities | Nessus | Windows | critical |
69267 | Thunderbird ESR 17.x < 17.0.8 Multiple Vulnerabilities (Mac OS X) | Nessus | MacOS X Local Security Checks | critical |
69266 | Thunderbird < 17.0.8 Multiple Vulnerabilities (Mac OS X) | Nessus | MacOS X Local Security Checks | critical |
69265 | Firefox < 23.0 Multiple Vulnerabilities (Mac OS X) | Nessus | MacOS X Local Security Checks | critical |
69264 | Firefox ESR 17.x < 17.0.8 Multiple Vulnerabilities (Mac OS X) | Nessus | MacOS X Local Security Checks | critical |
69260 | Ubuntu 12.04 LTS / 12.10 / 13.04 : thunderbird vulnerabilities (USN-1925-1) | Nessus | Ubuntu Local Security Checks | critical |
69258 | Scientific Linux Security Update : thunderbird on SL5.x, SL6.x i386/x86_64 (20130807) | Nessus | Scientific Linux Local Security Checks | critical |
69257 | Scientific Linux Security Update : firefox on SL5.x, SL6.x i386/x86_64 (20130807) | Nessus | Scientific Linux Local Security Checks | critical |
69255 | RHEL 5 / 6 : thunderbird (RHSA-2013:1142) | Nessus | Red Hat Local Security Checks | critical |
69254 | RHEL 5 / 6 : firefox (RHSA-2013:1140) | Nessus | Red Hat Local Security Checks | critical |
69252 | Oracle Linux 6 : thunderbird (ELSA-2013-1142) | Nessus | Oracle Linux Local Security Checks | critical |
69251 | Oracle Linux 5 / 6 : firefox (ELSA-2013-1140) | Nessus | Oracle Linux Local Security Checks | critical |
69246 | CentOS 5 / 6 : thunderbird (CESA-2013:1142) | Nessus | CentOS Local Security Checks | critical |
69245 | CentOS 5 / 6 : firefox (CESA-2013:1140) | Nessus | CentOS Local Security Checks | critical |
6979 | Mozilla Thunderbird < 17.0.8 Multiple Vulnerabilities | Nessus Network Monitor | SMTP Clients | high |
6978 | Mozilla Firefox < 23.0 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
6977 | SeaMonkey < 2.20 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
69235 | Ubuntu 12.04 LTS / 12.10 / 13.04 : ubufox, unity-firefox-extension update (USN-1924-2) | Nessus | Ubuntu Local Security Checks | critical |
69234 | Ubuntu 12.04 LTS / 12.10 / 13.04 : firefox vulnerabilities (USN-1924-1) | Nessus | Ubuntu Local Security Checks | critical |