CVE-2013-1730

MEDIUM

Description

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly handle movement of XBL-backed nodes between documents, which allows remote attackers to execute arbitrary code or cause a denial of service (JavaScript compartment mismatch, or assertion failure and application exit) via a crafted web site.

References

http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115907.html

http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116610.html

http://lists.fedoraproject.org/pipermail/package-announce/2013-September/117526.html

http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00005.html

http://lists.opensuse.org/opensuse-updates/2013-09/msg00055.html

http://lists.opensuse.org/opensuse-updates/2013-09/msg00057.html

http://lists.opensuse.org/opensuse-updates/2013-09/msg00059.html

http://lists.opensuse.org/opensuse-updates/2013-09/msg00060.html

http://lists.opensuse.org/opensuse-updates/2013-09/msg00061.html

http://rhn.redhat.com/errata/RHSA-2013-1268.html

http://rhn.redhat.com/errata/RHSA-2013-1269.html

http://www.debian.org/security/2013/dsa-2762

http://www.mozilla.org/security/announce/2013/mfsa2013-88.html

http://www.securityfocus.com/bid/62473

http://www.ubuntu.com/usn/USN-1951-1

http://www.ubuntu.com/usn/USN-1952-1

https://bugzilla.mozilla.org/show_bug.cgi?id=851353

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19022

Details

Source: MITRE

Published: 2013-09-18

Updated: 2017-09-19

Type: CWE-119

Risk Information

CVSS v2.0

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:mozilla:thunderbird:17.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:17.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:17.0.2:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:17.0.3:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:17.0.4:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:17.0.5:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:17.0.6:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:17.0.7:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:17.0.8:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* versions up to 17.0.9 (inclusive)

Configuration 2

OR

cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0:beta_1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0:beta_2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0:rc1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0:rc2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.2:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.3:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.4:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.5:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.6:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.7:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.8:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.9:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.10:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.11:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.12:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.13:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.0.14:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.1:alpha1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.1:alpha2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.1:alpha3:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.1:beta1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.1:beta2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.1:beta3:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.1:rc1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.1:rc2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.10:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.10:beta1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.10:beta2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.10:beta3:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.10.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.11:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.11:beta1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.11:beta2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.11:beta3:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.11:beta4:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.11:beta5:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.11:beta6:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.12:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.12:beta1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.12:beta2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.12:beta3:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.12:beta4:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.12:beta5:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.12:beta6:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.12.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.13:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.13:beta1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.13:beta2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.13:beta3:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.13:beta4:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.13:beta5:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.13:beta6:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.13.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.13.2:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.14:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.14:beta1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.14:beta2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.14:beta3:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.14:beta4:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.14:beta5:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.15:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.15:beta1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.15:beta2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.15:beta3:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.15:beta4:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.15:beta5:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.15:beta6:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.15.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.15.2:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.16:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.16:beta1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.16:beta2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.16:beta3:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.16:beta4:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.16:beta5:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.16.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.16.2:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.17:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.17:beta1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.17:beta2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.17:beta3:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.17:beta4:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.17.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.18:beta1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.18:beta2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.18:beta3:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.18:beta4:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.19:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.19:beta1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.19:beta2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* versions up to 2.20 (inclusive)

cpe:2.3:a:mozilla:seamonkey:2.20:beta1:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.20:beta2:*:*:*:*:*:*

cpe:2.3:a:mozilla:seamonkey:2.20:beta3:*:*:*:*:*:*

Configuration 3

OR

cpe:2.3:a:mozilla:firefox_esr:17.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox_esr:17.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox_esr:17.0.2:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox_esr:17.0.3:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox_esr:17.0.4:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox_esr:17.0.5:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox_esr:17.0.6:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox_esr:17.0.7:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox_esr:17.0.8:*:*:*:*:*:*:*

Configuration 4

OR

cpe:2.3:a:mozilla:firefox:19.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:19.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:19.0.2:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:20.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:20.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:21.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:22.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:23.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* versions up to 23.0.1 (inclusive)

Configuration 5

OR

cpe:2.3:a:mozilla:thunderbird_esr:17.0:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird_esr:17.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird_esr:17.0.2:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird_esr:17.0.3:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird_esr:17.0.4:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird_esr:17.0.5:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird_esr:17.0.6:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird_esr:17.0.7:*:*:*:*:*:*:*

cpe:2.3:a:mozilla:thunderbird_esr:17.0.8:*:*:*:*:*:*:*

Tenable Plugins

View all (36 total)

IDNameProductFamilySeverity
701237Mozilla Firefox ESR < 17.0.9 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
75186openSUSE Security Update : Mozilla Suite (openSUSE-SU-2013:1633-1)NessusSuSE Local Security Checks
critical
75151openSUSE Security Update : seamonkey (openSUSE-SU-2013:1491-1)NessusSuSE Local Security Checks
critical
75150openSUSE Security Update : MozillaThunderbird (openSUSE-SU-2013:1495-1)NessusSuSE Local Security Checks
critical
75149openSUSE Security Update : MozillaFirefox (openSUSE-SU-2013:1493-1)NessusSuSE Local Security Checks
critical
75148openSUSE Security Update : xulrunner17 (openSUSE-SU-2013:1496-1)NessusSuSE Local Security Checks
critical
70262FreeBSD : mozilla -- multiple vulnerabilities (7dfed67b-20aa-11e3-b8d8-0025905a4771)NessusFreeBSD Local Security Checks
critical
70205Fedora 18 : firefox-24.0-1.fc18 / xulrunner-24.0-2.fc18 (2013-17047)NessusFedora Local Security Checks
critical
70189SuSE 11.2 / 11.3 Security Update : Mozilla Firefox (SAT Patch Numbers 8344 / 8346)NessusSuSE Local Security Checks
critical
70183GLSA-201309-23 : Mozilla Products: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
70080Debian DSA-2762-1 : icedove - several vulnerabilitiesNessusDebian Local Security Checks
critical
70062Fedora 20 : firefox-24.0-1.fc20 / xulrunner-24.0-2.fc20 (2013-17074)NessusFedora Local Security Checks
critical
70036Fedora 19 : firefox-24.0-1.fc19 / xulrunner-24.0-2.fc19 (2013-16992)NessusFedora Local Security Checks
critical
69996SeaMonkey < 2.21 Multiple VulnerabilitiesNessusWindows
critical
69995Mozilla Thunderbird 17.x through 23.x Multiple VulnerabilitiesNessusWindows
critical
69994Mozilla Thunderbird ESR 17.x < 17.0.9 Multiple VulnerabilitiesNessusWindows
critical
69993Firefox < 24.0 Multiple VulnerabilitiesNessusWindows
critical
69992Firefox ESR 17.x < 17.0.9 Multiple VulnerabilitiesNessusWindows
critical
69991Thunderbird 17.x through 23.x Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
69990Thunderbird ESR 17.x < 17.0.9 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
69989Firefox < 24.0 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
69988Firefox ESR 17.x < 17.0.9 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
69970Ubuntu 12.04 LTS / 12.10 / 13.04 : thunderbird vulnerabilities (USN-1952-1)NessusUbuntu Local Security Checks
critical
69959Debian DSA-2759-1 : iceweasel - several vulnerabilitiesNessusDebian Local Security Checks
critical
8012SeaMonkey < 2.21 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
8011Mozilla Thunderbird < 24.0Nessus Network MonitorSMTP Clients
high
8010Mozilla Firefox < 24.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
69947Ubuntu 12.04 LTS / 12.10 / 13.04 : firefox vulnerabilities (USN-1951-1)NessusUbuntu Local Security Checks
critical
69946Scientific Linux Security Update : thunderbird on SL5.x, SL6.x i386/srpm/x86_64 (20130917)NessusScientific Linux Local Security Checks
critical
69945Scientific Linux Security Update : firefox on SL5.x, SL6.x i386/srpm/x86_64 (20130917)NessusScientific Linux Local Security Checks
critical
69944RHEL 5 / 6 : thunderbird (RHSA-2013:1269)NessusRed Hat Local Security Checks
critical
69943RHEL 5 / 6 : firefox (RHSA-2013:1268)NessusRed Hat Local Security Checks
critical
69941Oracle Linux 6 : thunderbird (ELSA-2013-1269)NessusOracle Linux Local Security Checks
critical
69940Oracle Linux 5 / 6 : firefox (ELSA-2013-1268)NessusOracle Linux Local Security Checks
critical
69937CentOS 5 / 6 : thunderbird (CESA-2013:1269)NessusCentOS Local Security Checks
critical
69936CentOS 5 / 6 : firefox (CESA-2013:1268)NessusCentOS Local Security Checks
critical