CVE
- Id
- 61672
- CVE No.
- CVE-2013-1725
- Status
- Candidate
- Description
- Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not ensure that initialization occurs for JavaScript objects with compartments, which allows remote attackers to execute arbitrary code by leveraging incorrect scope handling.
- Phase
- Assigned (20130213)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
617406 | 61672 | CVE-2013-1725 | CONFIRM:http://www.mozilla.org/security/announce/2013/mfsa2013-82.html | View |
617407 | 61672 | CVE-2013-1725 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=876762 | View |
617408 | 61672 | CVE-2013-1725 | DEBIAN:DSA-2762 | View |
617409 | 61672 | CVE-2013-1725 | URL:http://www.debian.org/security/2013/dsa-2762 | View |
617410 | 61672 | CVE-2013-1725 | FEDORA:FEDORA-2013-16992 | View |
617411 | 61672 | CVE-2013-1725 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115907.html | View |
617412 | 61672 | CVE-2013-1725 | FEDORA:FEDORA-2013-17047 | View |
617413 | 61672 | CVE-2013-1725 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2013-September/117526.html | View |
617414 | 61672 | CVE-2013-1725 | FEDORA:FEDORA-2013-17074 | View |
617415 | 61672 | CVE-2013-1725 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116610.html | View |
617416 | 61672 | CVE-2013-1725 | REDHAT:RHSA-2013:1268 | View |
617417 | 61672 | CVE-2013-1725 | URL:http://rhn.redhat.com/errata/RHSA-2013-1268.html | View |
617418 | 61672 | CVE-2013-1725 | REDHAT:RHSA-2013:1269 | View |
617419 | 61672 | CVE-2013-1725 | URL:http://rhn.redhat.com/errata/RHSA-2013-1269.html | View |
617420 | 61672 | CVE-2013-1725 | SUSE:openSUSE-SU-2013:1491 | View |
617421 | 61672 | CVE-2013-1725 | URL:http://lists.opensuse.org/opensuse-updates/2013-09/msg00055.html | View |
617422 | 61672 | CVE-2013-1725 | SUSE:openSUSE-SU-2013:1493 | View |
617423 | 61672 | CVE-2013-1725 | URL:http://lists.opensuse.org/opensuse-updates/2013-09/msg00057.html | View |
617424 | 61672 | CVE-2013-1725 | SUSE:openSUSE-SU-2013:1495 | View |
617425 | 61672 | CVE-2013-1725 | URL:http://lists.opensuse.org/opensuse-updates/2013-09/msg00059.html | View |
617426 | 61672 | CVE-2013-1725 | SUSE:openSUSE-SU-2013:1496 | View |
617427 | 61672 | CVE-2013-1725 | URL:http://lists.opensuse.org/opensuse-updates/2013-09/msg00060.html | View |
617428 | 61672 | CVE-2013-1725 | SUSE:openSUSE-SU-2013:1499 | View |
617429 | 61672 | CVE-2013-1725 | URL:http://lists.opensuse.org/opensuse-updates/2013-09/msg00061.html | View |
617430 | 61672 | CVE-2013-1725 | SUSE:openSUSE-SU-2013:1633 | View |
617431 | 61672 | CVE-2013-1725 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00005.html | View |
617432 | 61672 | CVE-2013-1725 | UBUNTU:USN-1951-1 | View |
617433 | 61672 | CVE-2013-1725 | URL:http://www.ubuntu.com/usn/USN-1951-1 | View |
617434 | 61672 | CVE-2013-1725 | UBUNTU:USN-1952-1 | View |
617435 | 61672 | CVE-2013-1725 | URL:http://www.ubuntu.com/usn/USN-1952-1 | View |
617436 | 61672 | CVE-2013-1725 | BID:62467 | View |
617437 | 61672 | CVE-2013-1725 | URL:http://www.securityfocus.com/bid/62467 | View |
617438 | 61672 | CVE-2013-1725 | OVAL:oval:org.mitre.oval:def:19025 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
22629 | JVNDB-2013-004204 | 複数の Mozilla 製品における任意のコードを実行される脆弱性 | Mozilla Firefox、Thunderbird、および SeaMonkey は、ドキュメント間の XBL 製ノードの移動を適切に処理しないため、任意のコードを実行される、またはサービス運用妨害 (JavaScript コンパートメントの不一致、または表明違反およびアプリケーションの終了) 状態にされる脆弱性が存在します。 | CVE-2013-1730 | 61672 | 6.8 | http://jvndb.jvn.jp/ja/contents/2013/JVNDB-2013-004204.html | View |