CVE Vulnerabilities

CVE-2013-1737

Published: Sep 18, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the this object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.

Affected Software

NameVendorStart VersionEnd Version
Thunderbird_esrMozilla17.0 (including)17.0 (including)
Thunderbird_esrMozilla17.0.1 (including)17.0.1 (including)
Thunderbird_esrMozilla17.0.2 (including)17.0.2 (including)
Thunderbird_esrMozilla17.0.3 (including)17.0.3 (including)
Thunderbird_esrMozilla17.0.4 (including)17.0.4 (including)
Thunderbird_esrMozilla17.0.5 (including)17.0.5 (including)
Thunderbird_esrMozilla17.0.6 (including)17.0.6 (including)
Thunderbird_esrMozilla17.0.7 (including)17.0.7 (including)
Thunderbird_esrMozilla17.0.8 (including)17.0.8 (including)
Red Hat Enterprise Linux 5RedHatthunderbird-0:17.0.9-1.el5_9*
Red Hat Enterprise Linux 5RedHatfirefox-0:17.0.9-1.el5_9*
Red Hat Enterprise Linux 5RedHatxulrunner-0:17.0.9-1.el5_9*
Red Hat Enterprise Linux 6RedHatfirefox-0:17.0.9-1.el6_4*
Red Hat Enterprise Linux 6RedHatxulrunner-0:17.0.9-1.el6_4*
Red Hat Enterprise Linux 6RedHatthunderbird-0:17.0.9-1.el6_4*
FirefoxUbuntudevel*
FirefoxUbuntulucid*
FirefoxUbuntuprecise*
FirefoxUbuntuquantal*
FirefoxUbunturaring*
FirefoxUbuntuupstream*
ThunderbirdUbuntudevel*
ThunderbirdUbuntulucid*
ThunderbirdUbuntuprecise*
ThunderbirdUbuntuquantal*
ThunderbirdUbunturaring*
ThunderbirdUbuntuupstream*

References