Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

ubuntu Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

CVE-2013-0746

ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 13 янв. 2013
Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: ubuntu
ΠŸΡ€ΠΈΠΎΡ€ΠΈΡ‚Π΅Ρ‚: medium
EPSS Низкий
CVSS2: 9.3

ОписаниС

Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 do not properly implement quickstubs that use the jsval data type for their return values, which allows remote attackers to execute arbitrary code or cause a denial of service (compartment mismatch and application crash) via crafted JavaScript code that is not properly handled during garbage collection.

Π Π΅Π»ΠΈΠ·Π‘Ρ‚Π°Ρ‚ΡƒΡΠŸΡ€ΠΈΠΌΠ΅Ρ‡Π°Π½ΠΈΠ΅
devel

released

19.0~b1+build2-0ubuntu1
hardy

ignored

end of life
lucid

released

18.0+build1-0ubuntu0.10.04.3
oneiric

released

18.0+build1-0ubuntu0.11.10.3
precise

released

18.0+build1-0ubuntu0.12.04.3
quantal

released

18.0+build1-0ubuntu0.12.10.3
raring

released

19.0~b1+build2-0ubuntu1
saucy

released

19.0~b1+build2-0ubuntu1
upstream

released

18.0

ΠŸΠΎΠΊΠ°Π·Ρ‹Π²Π°Ρ‚ΡŒ ΠΏΠΎ

Π Π΅Π»ΠΈΠ·Π‘Ρ‚Π°Ρ‚ΡƒΡΠŸΡ€ΠΈΠΌΠ΅Ρ‡Π°Π½ΠΈΠ΅
devel

DNE

hardy

ignored

end of life
lucid

ignored

end of life
oneiric

ignored

end of life
precise

DNE

quantal

DNE

raring

DNE

saucy

DNE

upstream

released

2.15

ΠŸΠΎΠΊΠ°Π·Ρ‹Π²Π°Ρ‚ΡŒ ΠΏΠΎ

Π Π΅Π»ΠΈΠ·Π‘Ρ‚Π°Ρ‚ΡƒΡΠŸΡ€ΠΈΠΌΠ΅Ρ‡Π°Π½ΠΈΠ΅
devel

released

17.0.2+build1-0ubuntu1
hardy

ignored

end of life
lucid

released

17.0.2+build1-0ubuntu0.10.04.1
oneiric

released

17.0.2+build1-0ubuntu0.11.10.1
precise

released

17.0.2+build1-0ubuntu0.12.04.1
quantal

released

17.0.2+build1-0ubuntu0.12.10.1
raring

released

17.0.2+build1-0ubuntu1
saucy

released

17.0.2+build1-0ubuntu1
upstream

released

17.0.2

ΠŸΠΎΠΊΠ°Π·Ρ‹Π²Π°Ρ‚ΡŒ ΠΏΠΎ

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 84%
0.02359
Низкий

9.3 Critical

CVSS2

БвязанныС уязвимости

redhat
ΠΏΠΎΡ‡Ρ‚ΠΈ 13 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 do not properly implement quickstubs that use the jsval data type for their return values, which allows remote attackers to execute arbitrary code or cause a denial of service (compartment mismatch and application crash) via crafted JavaScript code that is not properly handled during garbage collection.

nvd
ΠΏΠΎΡ‡Ρ‚ΠΈ 13 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 do not properly implement quickstubs that use the jsval data type for their return values, which allows remote attackers to execute arbitrary code or cause a denial of service (compartment mismatch and application crash) via crafted JavaScript code that is not properly handled during garbage collection.

debian
ΠΏΠΎΡ‡Ρ‚ΠΈ 13 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x ...

github
большС 3 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 do not properly implement quickstubs that use the jsval data type for their return values, which allows remote attackers to execute arbitrary code or cause a denial of service (compartment mismatch and application crash) via crafted JavaScript code that is not properly handled during garbage collection.

oracle-oval
ΠΏΠΎΡ‡Ρ‚ΠΈ 13 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

ELSA-2013-0145: thunderbird security update (CRITICAL)

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 84%
0.02359
Низкий

9.3 Critical

CVSS2

Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ CVE-2013-0746