Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-1720

Опубликовано: 18 сент. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8

Описание

The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 does not properly maintain the state of the insertion-mode stack for template elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer over-read) by triggering use of this stack in its empty state.

РелизСтатусПримечание
devel

released

24.0+build1-0ubuntu1
lucid

ignored

end of life
precise

released

24.0+build1-0ubuntu0.12.04.1
quantal

released

24.0+build1-0ubuntu0.12.10.1
raring

released

24.0+build1-0ubuntu0.13.04.1
upstream

released

24.0

Показывать по

РелизСтатусПримечание
devel

released

1:24.0+build1-0ubuntu1
lucid

ignored

end of life
precise

released

1:24.0+build1-0ubuntu0.12.04.1
quantal

released

1:24.0+build1-0ubuntu0.12.10.1
raring

released

1:24.0+build1-0ubuntu0.13.04.1
upstream

released

24.0

Показывать по

EPSS

Процентиль: 83%
0.0194
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

redhat
больше 12 лет назад

The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 does not properly maintain the state of the insertion-mode stack for template elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer over-read) by triggering use of this stack in its empty state.

nvd
больше 12 лет назад

The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 does not properly maintain the state of the insertion-mode stack for template elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer over-read) by triggering use of this stack in its empty state.

debian
больше 12 лет назад

The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tr ...

github
больше 3 лет назад

The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 does not properly maintain the state of the insertion-mode stack for template elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer over-read) by triggering use of this stack in its empty state.

EPSS

Процентиль: 83%
0.0194
Низкий

6.8 Medium

CVSS2