CVE-2013-0753
high · 9.3Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via crafted web content.
9.3
CVSS
51.3%
EPSS (exploit prob.)
99th
EPSS percentile
2013-01-13
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-416
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| mozilla | firefox | < 18.0 |
| mozilla | firefox | >= 10.0, < 10.0.12 |
| mozilla | firefox | >= 17.0, < 17.0.2 |
| mozilla | seamonkey | < 2.15 |
| mozilla | thunderbird | < 17.0.2 |
| mozilla | thunderbird_esr | >= 10.0, < 10.0.12 |
| mozilla | thunderbird_esr | >= 17.0, < 17.0.2 |
| opensuse | opensuse | 11.4 |
| opensuse | opensuse | 12.1 |
| opensuse | opensuse | 12.2 |
| suse | linux_enterprise_desktop | 10 |
| suse | linux_enterprise_desktop | 11 |
| suse | linux_enterprise_server | 10 |
| suse | linux_enterprise_server | 11 |
| suse | linux_enterprise_server | 11 |
| suse | linux_enterprise_software_development_kit | 10 |
| suse | linux_enterprise_software_development_kit | 11 |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_eus | 5.9 |
| redhat | enterprise_linux_eus | 6.3 |
| redhat | enterprise_linux_server | 5.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server_aus | 5.9 |
| redhat | enterprise_linux_workstation | 5.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| canonical | ubuntu_linux | 10.04 |
| canonical | ubuntu_linux | 11.10 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 12.10 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00017.html
- http://rhn.redhat.com/errata/RHSA-2013-0144.html
- http://rhn.redhat.com/errata/RHSA-2013-0145.html
- http://www.mozilla.org/security/announce/2013/mfsa2013-16.html
- http://www.ubuntu.com/usn/USN-1681-1
- http://www.ubuntu.com/usn/USN-1681-2
- http://www.ubuntu.com/usn/USN-1681-4
- https://bugzilla.mozilla.org/show_bug.cgi?id=814001
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17053
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00017.html
- http://rhn.redhat.com/errata/RHSA-2013-0144.html
- http://rhn.redhat.com/errata/RHSA-2013-0145.html
- http://www.mozilla.org/security/announce/2013/mfsa2013-16.html
- http://www.ubuntu.com/usn/USN-1681-1
- http://www.ubuntu.com/usn/USN-1681-2
- http://www.ubuntu.com/usn/USN-1681-4
- https://bugzilla.mozilla.org/show_bug.cgi?id=814001
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17053
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-0753