CVE-2013-0801
Summary
| CVE | CVE-2013-0801 |
|---|---|
| State | PUBLISHED |
| Assigner | mozilla |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-05-16 11:45:30 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 17.0 | All | All | All |
| Application | Mozilla | Firefox | 17.0.1 | All | All | All |
| Application | Mozilla | Firefox | 17.0.2 | All | All | All |
| Application | Mozilla | Firefox | 17.0.3 | All | All | All |
| Application | Mozilla | Firefox | 17.0.4 | All | All | All |
| Application | Mozilla | Firefox | 17.0.5 | All | All | All |
| Application | Mozilla | Firefox | 19.0 | All | All | All |
| Application | Mozilla | Firefox | 19.0.1 | All | All | All |
| Application | Mozilla | Firefox | 19.0.2 | All | All | All |
| Application | Mozilla | Firefox | 20.0 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Thunderbird | 17.0 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.1 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.3 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.4 | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.1 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.2 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.3 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.4 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 787283 – Assertion failure: i >= 0, at jsopcode.cpp:5820 or Crash [@ js::DecompileValueGenerator] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| [security-announce] openSUSE-SU-2013:0929-1: important: xulrunner to 17. | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| 849597 – Crash when inline script in an XML doc framed by <object> removes the <object> | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 852315 – plugin crash running script during plugin destruction | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| 866544 – [Mac] Buffer overflow of nsAutoTArray "breakState" | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| [security-announce] openSUSE-SU-2013:0825-1: important: MozillaFirefox: | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| USN-1823-1: Thunderbird vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| 808402 – FTP use-after-free crash [@nsInputStreamPump::Cancel] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| [security-announce] openSUSE-SU-2013:0834-1: important: MozillaThunderbi | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Mozilla Firefox and Thunderbird CVE-2013-0801 Memory Corruption Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| USN-1822-1: Firefox vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| [security-announce] openSUSE-SU-2013:0831-1: important: xulrunner to 17. | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| 864558 – It's a horrible idea to do |new JS::Value[n]| and not root it/its contents while filling it in, and while using it after | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Support / Security / Advisories / / MDVSA-2013:165 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Debian -- Security Information -- DSA-2699-1 iceweasel | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| MFSA 2013-41: Miscellaneous memory safety hazards (rv:21.0 / rv:17.0.6) | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| [security-announce] openSUSE-SU-2013:0946-1: important: MozillaFirefox: | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.