Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-5616

Опубликовано: 11 дек. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to mListeners event listeners.

РелизСтатусПримечание
devel

not-affected

lucid

ignored

end of life
precise

released

26.0+build2-0ubuntu0.12.04.2
quantal

released

26.0+build2-0ubuntu0.12.10.2
raring

released

26.0+build2-0ubuntu0.13.04.2
saucy

released

26.0+build2-0ubuntu0.13.10.2
upstream

released

26.0

Показывать по

РелизСтатусПримечание
devel

released

1:24.2.0+build1-0ubuntu1
lucid

ignored

end of life
precise

released

1:24.2.0+build1-0ubuntu0.12.04.1
quantal

released

1:24.2.0+build1-0ubuntu0.12.10.1
raring

released

1:24.2.0+build1-0ubuntu0.13.04.1
saucy

released

1:24.2.0+build1-0ubuntu0.13.10.1
upstream

released

24.2.0

Показывать по

EPSS

Процентиль: 83%
0.02107
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

redhat
больше 11 лет назад

Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to mListeners event listeners.

CVSS3: 9.8
nvd
больше 11 лет назад

Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to mListeners event listeners.

CVSS3: 9.8
debian
больше 11 лет назад

Use-after-free vulnerability in the nsEventListenerManager::HandleEven ...

CVSS3: 9.8
github
около 3 лет назад

Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to mListeners event listeners.

oracle-oval
больше 11 лет назад

ELSA-2013-1823: thunderbird security update (IMPORTANT)

EPSS

Процентиль: 83%
0.02107
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3