{"cves":[{"id":"CVE-2013-4469","published":"2013-11-02T00:00:00","updated_at":"2025-08-04T19:24:24.192941+00:00","description":"\nOpenStack Compute (Nova) Folsom, Grizzly, and Havana, when use_cow_images\nis set to False, does not verify the virtual size of a QCOW2 image, which\nallows local users to cause a denial of service (host file system disk\nconsumption) by transferring an image with a large virtual size that does\nnot contain a large amount of data from Glance. NOTE: this issue is due to\nan incomplete fix for CVE-2013-2096.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"patch for CVE-2013-4463 should fix this\nsaucy needs a no change rebuild for saucy-security"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/10/31/3","https://ubuntu.com/security/notices/USN-2247-1","https://www.cve.org/CVERecord?id=CVE-2013-4469"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=728605","https://bugzilla.redhat.com/show_bug.cgi?id=1023239","https://bugzilla.redhat.com/show_bug.cgi?id=1023581","http://launchpad.net/bugs/1206081"],"patches":{"nova":["vendor: https://bugzilla.redhat.com/attachment.cgi?id=816275&action=diff","vendor: https://bugzilla.redhat.com/attachment.cgi?id=816276&action=diff","vendor: https://bugzilla.redhat.com/attachment.cgi?id=816277&action=diff","upstream: https://github.com/openstack/nova/commit/f6810be4ae1a6c93e7d8017ee67d5344dfdf4a30","upstream: https://github.com/openstack/nova/commit/3cdfe894ab58f7b91bf7fb690fc5bc724e44066f","upstream: https://github.com/openstack/nova/commit/135faa7b5d9855312bedc19e5e1ecebae34d3d18","upstream: https://review.openstack.org/54767","upstream: https://review.openstack.org/54768"]},"tags":{},"packages":[{"name":"nova","source":"https://ubuntu.com/security/cve?package=nova","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nova","debian":"https://tracker.debian.org/pkg/nova","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2012.1.3+stable-20130423-e52e6912-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life, was pending","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:2013.2.3-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [1:2014.1~b1-0ubuntu2]]","component":null,"pocket":"security"}]}],"notices_ids":["USN-2247-1"],"notices":[{"id":"USN-2247-1","title":"OpenStack Nova vulnerabilities","summary":"Several security issues were fixed in OpenStack Nova.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-06-17T21:50:58.685639","description":"Darragh O'Reilly discovered that the Ubuntu packaging for OpenStack Nova\ndid not properly set up its sudo configuration. If a different flaw was\nfound in OpenStack Nova, this vulnerability could be used to escalate\nprivileges. This issue only affected Ubuntu 13.10 and Ubuntu 14.04 LTS.\n(CVE-2013-1068)\n\nBernhard M. Wiedemann and Pedraig Brady discovered that OpenStack Nova did\nnot properly verify the virtual size of a QCOW2 images. A remote\nauthenticated attacker could exploit this to create a denial of service via\ndisk consumption. This issue did not affect Ubuntu 14.04 LTS.\n(CVE-2013-4463, CVE-2013-4469)\n\nJuanFra Rodriguez Cardoso discovered that OpenStack Nova did not enforce\nSSL connections when Nova was configured to use QPid and qpid_protocol is\nset to 'ssl'. If a remote attacker were able to perform a machine-in-the-middle\nattack, this flaw could be exploited to view sensitive information. Ubuntu\ndoes not use QPid with Nova by default. This issue did not affect Ubuntu\n14.04 LTS. (CVE-2013-6491)\n\nLoganathan Parthipan discovered that OpenStack Nova did not properly create\nexpected files during KVM live block migration. A remote authenticated\nattacker could exploit this to obtain root disk snapshot contents via\nephemeral storage. This issue did not affect Ubuntu 14.04 LTS.\n(CVE-2013-7130)\n\nStanislaw Pitucha discovered that OpenStack Nova did not enforce the image\nformat when rescuing an instance. A remote authenticated attacker could\nexploit this to read host files. In the default installation, attackers\nwould be isolated by the libvirt guest AppArmor profile. This issue only\naffected Ubuntu 13.10. (CVE-2014-0134)\n\nMark Heckmann discovered that OpenStack Nova did not enforce RBAC policy\nwhen adding security group rules via the EC2 API. A remote authenticated\nuser could exploit this to gain unintended access to this API. This issue\nonly affected Ubuntu 13.10. (CVE-2014-0167)\n","is_hidden":false,"release_packages":{"precise":[{"name":"nova","version":"2012.1.3+stable-20130423-e52e6912-0ubuntu1.4","description":"OpenStack Compute cloud infrastructure","is_source":true},{"name":"python-nova","version":"2012.1.3+stable-20130423-e52e6912-0ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/2012.1.3+stable-20130423-e52e6912-0ubuntu1.4"}],"saucy":[{"name":"nova","version":"1:2013.2.3-0ubuntu1.2","description":"OpenStack Compute cloud infrastructure","is_source":true},{"name":"python-nova","version":"1:2013.2.3-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2013.2.3-0ubuntu1.2"}],"trusty":[{"name":"nova","version":"1:2014.1-0ubuntu1.2","description":"OpenStack Compute cloud infrastructure","is_source":true},{"name":"nova-ajax-console-proxy","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-api","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-api-ec2","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-api-metadata","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-api-os-compute","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-api-os-volume","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-baremetal","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-cells","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-cert","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-common","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-compute","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-compute-kvm","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-compute-libvirt","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-compute-lxc","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-compute-qemu","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-compute-vmware","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-compute-xen","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-conductor","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-console","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-consoleauth","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-doc","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-network","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-novncproxy","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-objectstore","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-scheduler","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-spiceproxy","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-volume","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-xvpvncproxy","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"python-nova","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2013-1068","CVE-2013-4463","CVE-2013-4469","CVE-2013-6491","CVE-2013-7130","CVE-2014-0134","CVE-2014-0167"]}]},{"id":"CVE-2013-4401","published":"2013-11-02T00:00:00","updated_at":"2025-08-04T19:24:22.608699+00:00","description":"\nThe virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3\nchecks for the connect:read permission instead of the connect:write\npermission, which allows attackers to gain domain:write privileges and\nexecute Qemu binaries via crafted XML. NOTE: some of these details are\nobtained from third party information.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in 1.1.0"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2026-1","https://www.cve.org/CVERecord?id=CVE-2013-4401"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=727101","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4401","https://bugzilla.redhat.com/show_bug.cgi?id=1012196"],"patches":{"libvirt":["upstream: http://libvirt.org/git/?p=libvirt.git;a=commit;h=57687fd6bf7f6e1b3662c52f3f26c06ab19dc96c"]},"tags":{},"packages":[{"name":"libvirt","source":"https://ubuntu.com/security/cve?package=libvirt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvirt","debian":"https://tracker.debian.org/pkg/libvirt","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.0.2-0ubuntu11.13.04.4","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1.1.1-0ubuntu8.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2026-1"],"notices":[{"id":"USN-2026-1","title":"libvirt vulnerability","summary":"libvirt would allow unintended access privileges.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2013-11-11T15:45:57.713102","description":"It was discovered that libvirt incorrectly checked privileges when the\nvirConnectDomainXMLToNative API function was used. An attacker could\npossibly use this flaw to gain write privileges, contrary to expected\nbehaviour.\n","is_hidden":false,"release_packages":{"saucy":[{"name":"libvirt","version":"1.1.1-0ubuntu8.1","description":"Libvirt virtualization toolkit","is_source":true},{"name":"libvirt0","version":"1.1.1-0ubuntu8.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/1.1.1-0ubuntu8.1"}]},"type":"USN","cves_ids":["CVE-2013-4401"]}]},{"id":"CVE-2013-4282","published":"2013-11-02T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in the reds_handle_ticket function in\nserver/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of\nservice (crash) via a long password in a SPICE ticket.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://rhn.redhat.com/errata/RHSA-2013-1474.html","http://rhn.redhat.com/errata/RHSA-2013-1473.html","http://rhn.redhat.com/errata/RHSA-2013-1460.html","https://ubuntu.com/security/notices/USN-2027-1","https://www.cve.org/CVERecord?id=CVE-2013-4282"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=728314"],"patches":{"spice":["upstream: http://cgit.freedesktop.org/spice/spice/commit/?id=8af619009660b24e0b41ad26b30289eea288fcc2"]},"tags":{},"packages":[{"name":"spice","source":"https://ubuntu.com/security/cve?package=spice","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=spice","debian":"https://tracker.debian.org/pkg/spice","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"0.12.2-0nocelt2expubuntu1.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"0.12.4-0nocelt1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.12.4-0nocelt1.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.12.4-0nocelt2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"0.12.4-0nocelt1.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"0.12.4-0nocelt1.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.12.4-0nocelt1.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.12.4-0nocelt1.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"0.12.4-0nocelt1.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"0.12.4-0nocelt1.1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2027-1"],"notices":[{"id":"USN-2027-1","title":"SPICE vulnerability","summary":"SPICE could be made to crash if it received specially crafted network\ntraffic.\n","instructions":"After a standard system update you need to restart applications using the\nSPICE protocol, such as QEMU, to make all the necessary changes.\n","references":[],"published":"2013-11-12T13:05:29.660216","description":"Tomas Jamrisko discovered that SPICE incorrectly handled long passwords in\nSPICE tickets. An attacker could use this issue to cause the SPICE server\nto crash, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"saucy":[{"name":"spice","version":"0.12.4-0nocelt1ubuntu0.1","description":"SPICE protocol client and server library","is_source":true},{"name":"libspice-server1","version":"0.12.4-0nocelt1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/spice","version_link":"https://launchpad.net/ubuntu/+source/spice/0.12.4-0nocelt1ubuntu0.1"}],"raring":[{"name":"spice","version":"0.12.2-0nocelt2expubuntu1.2","description":"SPICE protocol client and server library","is_source":true},{"name":"libspice-server1","version":"0.12.2-0nocelt2expubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/spice","version_link":"https://launchpad.net/ubuntu/+source/spice/0.12.2-0nocelt2expubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2013-4282"]}]},{"id":"CVE-2013-2065","published":"2013-11-02T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\n(1) DL and (2) Fiddle in Ruby 1.9 before 1.9.3 patchlevel 426, and 2.0\nbefore 2.0.0 patchlevel 195, do not perform taint checking for native\nfunctions, which allows context-dependent attackers to bypass intended\n$SAFE level restrictions.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"only affects 1.9+"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.ruby-lang.org/en/news/2013/05/14/taint-bypass-dl-fiddle-cve-2013-2065/","http://lists.opensuse.org/opensuse-updates/2013-10/msg00057.html","https://ubuntu.com/security/notices/USN-2035-1","https://www.cve.org/CVERecord?id=CVE-2013-2065"],"bugs":[""],"patches":{"ruby1.8":[],"ruby1.9.1":["upstream: http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=40732","upstream: http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=40728"],"ruby2.0":[]},"tags":{},"packages":[{"name":"ruby1.8","source":"https://ubuntu.com/security/cve?package=ruby1.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.8","debian":"https://tracker.debian.org/pkg/ruby1.8","statuses":[{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"ruby1.9.1","source":"https://ubuntu.com/security/cve?package=ruby1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.9.1","debian":"https://tracker.debian.org/pkg/ruby1.9.1","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.9.3.0-1ubuntu2.8","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1.9.3.194-1ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1.9.3.194-8.1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1.9.3.194-8.1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.3.426","component":null,"pocket":"security"}]},{"name":"ruby2.0","source":"https://ubuntu.com/security/cve?package=ruby2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby2.0","debian":"https://tracker.debian.org/pkg/ruby2.0","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"2.0.0.299-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.195","component":null,"pocket":"security"}]}],"notices_ids":["USN-2035-1"],"notices":[{"id":"USN-2035-1","title":"Ruby vulnerabilities","summary":"Several security issues were fixed in Ruby.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2013-11-27T16:36:42.251615","description":"Charlie Somerville discovered that Ruby incorrectly handled floating point\nnumber conversion. An attacker could possibly use this issue with an\napplication that converts text to floating point numbers to cause the\napplication to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2013-4164)\n\nVit Ondruch discovered that Ruby did not perform taint checking for certain\nfunctions. An attacker could possibly use this issue to bypass certain\nintended restrictions. (CVE-2013-2065)\n","is_hidden":false,"release_packages":{"precise":[{"name":"ruby1.8","version":"1.8.7.352-2ubuntu1.4","description":"Object-oriented scripting language","is_source":true},{"name":"ruby1.9.1","version":"1.9.3.0-1ubuntu2.8","description":"Object-oriented scripting language","is_source":true},{"name":"ruby1.8","version":"1.8.7.352-2ubuntu1.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.352-2ubuntu1.4"},{"name":"ruby1.9.1","version":"1.9.3.0-1ubuntu2.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.0-1ubuntu2.8"},{"name":"libruby1.8","version":"1.8.7.352-2ubuntu1.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.352-2ubuntu1.4"},{"name":"libruby1.9.1","version":"1.9.3.0-1ubuntu2.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.0-1ubuntu2.8"}],"saucy":[{"name":"ruby1.8","version":"1.8.7.358-7ubuntu2.1","description":"Object-oriented scripting language","is_source":true},{"name":"ruby1.9.1","version":"1.9.3.194-8.1ubuntu2.1","description":"Object-oriented scripting language","is_source":true},{"name":"ruby1.8","version":"1.8.7.358-7ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.358-7ubuntu2.1"},{"name":"ruby1.9.1","version":"1.9.3.194-8.1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.194-8.1ubuntu2.1"},{"name":"libruby1.8","version":"1.8.7.358-7ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.358-7ubuntu2.1"},{"name":"libruby1.9.1","version":"1.9.3.194-8.1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.194-8.1ubuntu2.1"}],"quantal":[{"name":"ruby1.8","version":"1.8.7.358-4ubuntu0.4","description":"Object-oriented scripting language","is_source":true},{"name":"ruby1.9.1","version":"1.9.3.194-1ubuntu1.6","description":"Object-oriented scripting language","is_source":true},{"name":"ruby1.8","version":"1.8.7.358-4ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.358-4ubuntu0.4"},{"name":"ruby1.9.1","version":"1.9.3.194-1ubuntu1.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.194-1ubuntu1.6"},{"name":"libruby1.8","version":"1.8.7.358-4ubuntu0.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.358-4ubuntu0.4"},{"name":"libruby1.9.1","version":"1.9.3.194-1ubuntu1.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.194-1ubuntu1.6"}],"raring":[{"name":"ruby1.8","version":"1.8.7.358-7ubuntu1.2","description":"Object-oriented scripting language","is_source":true},{"name":"ruby1.9.1","version":"1.9.3.194-8.1ubuntu1.2","description":"Object-oriented scripting language","is_source":true},{"name":"ruby1.8","version":"1.8.7.358-7ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.358-7ubuntu1.2"},{"name":"ruby1.9.1","version":"1.9.3.194-8.1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.194-8.1ubuntu1.2"},{"name":"libruby1.8","version":"1.8.7.358-7ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.358-7ubuntu1.2"},{"name":"libruby1.9.1","version":"1.9.3.194-8.1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.194-8.1ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2013-2065","CVE-2013-4164"]}]},{"id":"CVE-2013-4484","published":"2013-11-01T02:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nVarnish before 3.0.5 allows remote attackers to cause a denial of service\n(child-process crash and temporary caching outage) via a GET request with\ntrailing whitespace characters and no URI.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.varnish-cache.org/trac/ticket/1367","http://archives.neohapsis.com/archives/bugtraq/current/0158.html","https://www.cve.org/CVERecord?id=CVE-2013-4484"],"bugs":[""],"patches":{"varnish":[]},"tags":{},"packages":[{"name":"varnish","source":"https://ubuntu.com/security/cve?package=varnish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=varnish","debian":"https://tracker.debian.org/pkg/varnish","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.0.5-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.0.5-2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.0.5-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.0.5-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.0.5-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.0.5-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"3.0.5-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-3630","published":"2013-11-01T02:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMoodle through 2.5.2 allows remote authenticated administrators to execute\narbitrary programs by configuring the aspell pathname and then triggering a\nspell-check operation within the TinyMCE editor.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://tracker.moodle.org/browse/MDL-41449","https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats","https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-foss-disclosures-part-one","https://www.cve.org/CVERecord?id=CVE-2013-3630"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5604","published":"2013-10-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla\nFirefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1,\nThunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey\nbefore 2.22 does not properly initialize data, which allows remote\nattackers to execute arbitrary code or cause a denial of service\n(stack-based buffer overflow and application crash) via crafted documents.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-95.html","https://ubuntu.com/security/notices/USN-2009-1","https://ubuntu.com/security/notices/USN-2010-1","https://www.cve.org/CVERecord?id=CVE-2013-5604"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0+build3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0+build3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0+build3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0+build3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.1.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2010-1","USN-2009-1"],"notices":[{"id":"USN-2010-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245422"],"published":"2013-10-31T12:48:46.252086","description":"Multiple memory safety issues were discovered in Thunderbird. If a user\nwere tricked in to opening a specially crafted message with scripting\nenabled, an attacker could possibly exploit these to cause a denial of\nservice via application crash, or potentially execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-1739,\nCVE-2013-5590, CVE-2013-5591)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. If a user had scripting enabled, an attacker could potentially\nexploit this to conduct URL spoofing or clickjacking attacks.\n(CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. If a user had scripting enabled, an attacker could\npotentially exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. If a user had\nenabled scripting, when combined with other vulnerabilities an attacker\ncould possibly exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. If a user had\nscripting enabled, an attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Thunderbird.\n(CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. If a user had scripting enabled, an attacker could potentially\nexploit this to cause a denial of service via application crash or\nexecute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5597)\n\nMultiple use-after-free flaws were discovered in Thunderbird. If a user\nhad scripting enabled, an attacker could potentially exploit these to\ncause a denial of service via application crash or execute arbitrary code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-5599,\nCVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. If a user had scripting enabled, an\nattacker could potentially exploit this to cause a denial of service\nvia application crash or execute arbitrary code with the privileges of\nthe user invoking Thunderbird. (CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. If a user had scripting enabled, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5593","CVE-2013-5604","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603"]},{"id":"USN-2009-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245414"],"published":"2013-10-29T19:18:10.283611","description":"Multiple memory safety issues were discovered in Firefox. If a user were\ntricked in to opening a specially crafted page, an attacker could possibly\nexploit these to cause a denial of service via application crash, or\npotentially execute arbitrary code with the privileges of the user\ninvoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,\nCVE-2013-5592)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. An attacker could potentially exploit this to conduct\nURL spoofing or clickjacking attacks (CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. An attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. When combined\nwith other vulnerabilities, an attacked could possibly exploit this\nto execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. An attacked\ncould potentially exploit this to execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. An attacker could potentially exploit this to cause a denial of\nservice via application crash or execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5597)\n\nCody Crews discovered a way to append an iframe in to an embedded PDF\nobject displayed with PDF.js. An attacked could potentially exploit this\nto read local files, leading to information disclosure. (CVE-2013-5598)\n\nMultiple use-after-free flaws were discovered in Firefox. An attacker\ncould potentially exploit these to cause a denial of service via\napplication crash or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5599, CVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. An attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. An attacker could potentially exploit this to cause\na denial of service via application crash or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.04.1"}],"saucy":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.10.1"}],"quantal":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.10.1"}],"raring":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5592","CVE-2013-5593","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5598","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603","CVE-2013-5604"]}]},{"id":"CVE-2013-5603","published":"2013-10-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the\nnsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla\nFirefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1,\nand SeaMonkey before 2.22 allows remote attackers to execute arbitrary code\nor cause a denial of service (heap memory corruption) via vectors involving\nHTML document templates.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-102.html","https://ubuntu.com/security/notices/USN-2009-1","https://ubuntu.com/security/notices/USN-2010-1","https://www.cve.org/CVERecord?id=CVE-2013-5603"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0+build3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0+build3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0+build3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0+build3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.1.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2010-1","USN-2009-1"],"notices":[{"id":"USN-2010-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245422"],"published":"2013-10-31T12:48:46.252086","description":"Multiple memory safety issues were discovered in Thunderbird. If a user\nwere tricked in to opening a specially crafted message with scripting\nenabled, an attacker could possibly exploit these to cause a denial of\nservice via application crash, or potentially execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-1739,\nCVE-2013-5590, CVE-2013-5591)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. If a user had scripting enabled, an attacker could potentially\nexploit this to conduct URL spoofing or clickjacking attacks.\n(CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. If a user had scripting enabled, an attacker could\npotentially exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. If a user had\nenabled scripting, when combined with other vulnerabilities an attacker\ncould possibly exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. If a user had\nscripting enabled, an attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Thunderbird.\n(CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. If a user had scripting enabled, an attacker could potentially\nexploit this to cause a denial of service via application crash or\nexecute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5597)\n\nMultiple use-after-free flaws were discovered in Thunderbird. If a user\nhad scripting enabled, an attacker could potentially exploit these to\ncause a denial of service via application crash or execute arbitrary code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-5599,\nCVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. If a user had scripting enabled, an\nattacker could potentially exploit this to cause a denial of service\nvia application crash or execute arbitrary code with the privileges of\nthe user invoking Thunderbird. (CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. If a user had scripting enabled, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5593","CVE-2013-5604","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603"]},{"id":"USN-2009-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245414"],"published":"2013-10-29T19:18:10.283611","description":"Multiple memory safety issues were discovered in Firefox. If a user were\ntricked in to opening a specially crafted page, an attacker could possibly\nexploit these to cause a denial of service via application crash, or\npotentially execute arbitrary code with the privileges of the user\ninvoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,\nCVE-2013-5592)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. An attacker could potentially exploit this to conduct\nURL spoofing or clickjacking attacks (CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. An attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. When combined\nwith other vulnerabilities, an attacked could possibly exploit this\nto execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. An attacked\ncould potentially exploit this to execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. An attacker could potentially exploit this to cause a denial of\nservice via application crash or execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5597)\n\nCody Crews discovered a way to append an iframe in to an embedded PDF\nobject displayed with PDF.js. An attacked could potentially exploit this\nto read local files, leading to information disclosure. (CVE-2013-5598)\n\nMultiple use-after-free flaws were discovered in Firefox. An attacker\ncould potentially exploit these to cause a denial of service via\napplication crash or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5599, CVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. An attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. An attacker could potentially exploit this to cause\na denial of service via application crash or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.04.1"}],"saucy":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.10.1"}],"quantal":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.10.1"}],"raring":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5592","CVE-2013-5593","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5598","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603","CVE-2013-5604"]}]},{"id":"CVE-2013-5602","published":"2013-10-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Worker::SetEventListener function in the Web workers implementation in\nMozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x\nbefore 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10,\nand SeaMonkey before 2.22 allows remote attackers to execute arbitrary code\nor cause a denial of service (memory corruption) via vectors related to\ndirect proxies.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-101.html","https://ubuntu.com/security/notices/USN-2009-1","https://ubuntu.com/security/notices/USN-2010-1","https://www.cve.org/CVERecord?id=CVE-2013-5602"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0+build3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0+build3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0+build3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0+build3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.1.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2010-1","USN-2009-1"],"notices":[{"id":"USN-2010-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245422"],"published":"2013-10-31T12:48:46.252086","description":"Multiple memory safety issues were discovered in Thunderbird. If a user\nwere tricked in to opening a specially crafted message with scripting\nenabled, an attacker could possibly exploit these to cause a denial of\nservice via application crash, or potentially execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-1739,\nCVE-2013-5590, CVE-2013-5591)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. If a user had scripting enabled, an attacker could potentially\nexploit this to conduct URL spoofing or clickjacking attacks.\n(CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. If a user had scripting enabled, an attacker could\npotentially exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. If a user had\nenabled scripting, when combined with other vulnerabilities an attacker\ncould possibly exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. If a user had\nscripting enabled, an attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Thunderbird.\n(CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. If a user had scripting enabled, an attacker could potentially\nexploit this to cause a denial of service via application crash or\nexecute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5597)\n\nMultiple use-after-free flaws were discovered in Thunderbird. If a user\nhad scripting enabled, an attacker could potentially exploit these to\ncause a denial of service via application crash or execute arbitrary code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-5599,\nCVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. If a user had scripting enabled, an\nattacker could potentially exploit this to cause a denial of service\nvia application crash or execute arbitrary code with the privileges of\nthe user invoking Thunderbird. (CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. If a user had scripting enabled, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5593","CVE-2013-5604","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603"]},{"id":"USN-2009-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245414"],"published":"2013-10-29T19:18:10.283611","description":"Multiple memory safety issues were discovered in Firefox. If a user were\ntricked in to opening a specially crafted page, an attacker could possibly\nexploit these to cause a denial of service via application crash, or\npotentially execute arbitrary code with the privileges of the user\ninvoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,\nCVE-2013-5592)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. An attacker could potentially exploit this to conduct\nURL spoofing or clickjacking attacks (CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. An attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. When combined\nwith other vulnerabilities, an attacked could possibly exploit this\nto execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. An attacked\ncould potentially exploit this to execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. An attacker could potentially exploit this to cause a denial of\nservice via application crash or execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5597)\n\nCody Crews discovered a way to append an iframe in to an embedded PDF\nobject displayed with PDF.js. An attacked could potentially exploit this\nto read local files, leading to information disclosure. (CVE-2013-5598)\n\nMultiple use-after-free flaws were discovered in Firefox. An attacker\ncould potentially exploit these to cause a denial of service via\napplication crash or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5599, CVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. An attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. An attacker could potentially exploit this to cause\na denial of service via application crash or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.04.1"}],"saucy":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.10.1"}],"quantal":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.10.1"}],"raring":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5592","CVE-2013-5593","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5598","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603","CVE-2013-5604"]}]},{"id":"CVE-2013-5601","published":"2013-10-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the nsEventListenerManager::SetEventHandler\nfunction in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10\nand 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before\n17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute\narbitrary code via vectors related to a memory allocation through the\ngarbage collection (GC) API.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-100.html","https://ubuntu.com/security/notices/USN-2009-1","https://ubuntu.com/security/notices/USN-2010-1","https://www.cve.org/CVERecord?id=CVE-2013-5601"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0+build3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0+build3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0+build3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0+build3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.1.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2010-1","USN-2009-1"],"notices":[{"id":"USN-2010-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245422"],"published":"2013-10-31T12:48:46.252086","description":"Multiple memory safety issues were discovered in Thunderbird. If a user\nwere tricked in to opening a specially crafted message with scripting\nenabled, an attacker could possibly exploit these to cause a denial of\nservice via application crash, or potentially execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-1739,\nCVE-2013-5590, CVE-2013-5591)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. If a user had scripting enabled, an attacker could potentially\nexploit this to conduct URL spoofing or clickjacking attacks.\n(CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. If a user had scripting enabled, an attacker could\npotentially exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. If a user had\nenabled scripting, when combined with other vulnerabilities an attacker\ncould possibly exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. If a user had\nscripting enabled, an attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Thunderbird.\n(CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. If a user had scripting enabled, an attacker could potentially\nexploit this to cause a denial of service via application crash or\nexecute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5597)\n\nMultiple use-after-free flaws were discovered in Thunderbird. If a user\nhad scripting enabled, an attacker could potentially exploit these to\ncause a denial of service via application crash or execute arbitrary code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-5599,\nCVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. If a user had scripting enabled, an\nattacker could potentially exploit this to cause a denial of service\nvia application crash or execute arbitrary code with the privileges of\nthe user invoking Thunderbird. (CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. If a user had scripting enabled, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5593","CVE-2013-5604","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603"]},{"id":"USN-2009-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245414"],"published":"2013-10-29T19:18:10.283611","description":"Multiple memory safety issues were discovered in Firefox. If a user were\ntricked in to opening a specially crafted page, an attacker could possibly\nexploit these to cause a denial of service via application crash, or\npotentially execute arbitrary code with the privileges of the user\ninvoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,\nCVE-2013-5592)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. An attacker could potentially exploit this to conduct\nURL spoofing or clickjacking attacks (CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. An attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. When combined\nwith other vulnerabilities, an attacked could possibly exploit this\nto execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. An attacked\ncould potentially exploit this to execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. An attacker could potentially exploit this to cause a denial of\nservice via application crash or execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5597)\n\nCody Crews discovered a way to append an iframe in to an embedded PDF\nobject displayed with PDF.js. An attacked could potentially exploit this\nto read local files, leading to information disclosure. (CVE-2013-5598)\n\nMultiple use-after-free flaws were discovered in Firefox. An attacker\ncould potentially exploit these to cause a denial of service via\napplication crash or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5599, CVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. An attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. An attacker could potentially exploit this to cause\na denial of service via application crash or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.04.1"}],"saucy":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.10.1"}],"quantal":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.10.1"}],"raring":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5592","CVE-2013-5593","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5598","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603","CVE-2013-5604"]}]},{"id":"CVE-2013-5600","published":"2013-10-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the\nnsIOService::NewChannelFromURIWithProxyFlags function in Mozilla Firefox\nbefore 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1,\nThunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey\nbefore 2.22 allows remote attackers to execute arbitrary code via vectors\ninvolving a blob: URL.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-100.html","https://ubuntu.com/security/notices/USN-2009-1","https://ubuntu.com/security/notices/USN-2010-1","https://www.cve.org/CVERecord?id=CVE-2013-5600"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0+build3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0+build3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0+build3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0+build3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.1.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2010-1","USN-2009-1"],"notices":[{"id":"USN-2010-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245422"],"published":"2013-10-31T12:48:46.252086","description":"Multiple memory safety issues were discovered in Thunderbird. If a user\nwere tricked in to opening a specially crafted message with scripting\nenabled, an attacker could possibly exploit these to cause a denial of\nservice via application crash, or potentially execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-1739,\nCVE-2013-5590, CVE-2013-5591)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. If a user had scripting enabled, an attacker could potentially\nexploit this to conduct URL spoofing or clickjacking attacks.\n(CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. If a user had scripting enabled, an attacker could\npotentially exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. If a user had\nenabled scripting, when combined with other vulnerabilities an attacker\ncould possibly exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. If a user had\nscripting enabled, an attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Thunderbird.\n(CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. If a user had scripting enabled, an attacker could potentially\nexploit this to cause a denial of service via application crash or\nexecute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5597)\n\nMultiple use-after-free flaws were discovered in Thunderbird. If a user\nhad scripting enabled, an attacker could potentially exploit these to\ncause a denial of service via application crash or execute arbitrary code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-5599,\nCVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. If a user had scripting enabled, an\nattacker could potentially exploit this to cause a denial of service\nvia application crash or execute arbitrary code with the privileges of\nthe user invoking Thunderbird. (CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. If a user had scripting enabled, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5593","CVE-2013-5604","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603"]},{"id":"USN-2009-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245414"],"published":"2013-10-29T19:18:10.283611","description":"Multiple memory safety issues were discovered in Firefox. If a user were\ntricked in to opening a specially crafted page, an attacker could possibly\nexploit these to cause a denial of service via application crash, or\npotentially execute arbitrary code with the privileges of the user\ninvoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,\nCVE-2013-5592)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. An attacker could potentially exploit this to conduct\nURL spoofing or clickjacking attacks (CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. An attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. When combined\nwith other vulnerabilities, an attacked could possibly exploit this\nto execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. An attacked\ncould potentially exploit this to execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. An attacker could potentially exploit this to cause a denial of\nservice via application crash or execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5597)\n\nCody Crews discovered a way to append an iframe in to an embedded PDF\nobject displayed with PDF.js. An attacked could potentially exploit this\nto read local files, leading to information disclosure. (CVE-2013-5598)\n\nMultiple use-after-free flaws were discovered in Firefox. An attacker\ncould potentially exploit these to cause a denial of service via\napplication crash or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5599, CVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. An attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. An attacker could potentially exploit this to cause\na denial of service via application crash or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.04.1"}],"saucy":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.10.1"}],"quantal":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.10.1"}],"raring":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5592","CVE-2013-5593","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5598","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603","CVE-2013-5604"]}]},{"id":"CVE-2013-5599","published":"2013-10-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the nsIPresShell::GetPresContext function\nin the PresShell (aka presentation shell) implementation in Mozilla Firefox\nbefore 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1,\nThunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey\nbefore 2.22 allows remote attackers to execute arbitrary code or cause a\ndenial of service (heap memory corruption and application crash) via\nvectors involving a CANVAS element, a mozTextStyle attribute, and an\nonresize event.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-100.html","https://ubuntu.com/security/notices/USN-2009-1","https://ubuntu.com/security/notices/USN-2010-1","https://www.cve.org/CVERecord?id=CVE-2013-5599"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0+build3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0+build3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0+build3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0+build3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.1.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2010-1","USN-2009-1"],"notices":[{"id":"USN-2010-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245422"],"published":"2013-10-31T12:48:46.252086","description":"Multiple memory safety issues were discovered in Thunderbird. If a user\nwere tricked in to opening a specially crafted message with scripting\nenabled, an attacker could possibly exploit these to cause a denial of\nservice via application crash, or potentially execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-1739,\nCVE-2013-5590, CVE-2013-5591)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. If a user had scripting enabled, an attacker could potentially\nexploit this to conduct URL spoofing or clickjacking attacks.\n(CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. If a user had scripting enabled, an attacker could\npotentially exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. If a user had\nenabled scripting, when combined with other vulnerabilities an attacker\ncould possibly exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. If a user had\nscripting enabled, an attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Thunderbird.\n(CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. If a user had scripting enabled, an attacker could potentially\nexploit this to cause a denial of service via application crash or\nexecute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5597)\n\nMultiple use-after-free flaws were discovered in Thunderbird. If a user\nhad scripting enabled, an attacker could potentially exploit these to\ncause a denial of service via application crash or execute arbitrary code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-5599,\nCVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. If a user had scripting enabled, an\nattacker could potentially exploit this to cause a denial of service\nvia application crash or execute arbitrary code with the privileges of\nthe user invoking Thunderbird. (CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. If a user had scripting enabled, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5593","CVE-2013-5604","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603"]},{"id":"USN-2009-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245414"],"published":"2013-10-29T19:18:10.283611","description":"Multiple memory safety issues were discovered in Firefox. If a user were\ntricked in to opening a specially crafted page, an attacker could possibly\nexploit these to cause a denial of service via application crash, or\npotentially execute arbitrary code with the privileges of the user\ninvoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,\nCVE-2013-5592)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. An attacker could potentially exploit this to conduct\nURL spoofing or clickjacking attacks (CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. An attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. When combined\nwith other vulnerabilities, an attacked could possibly exploit this\nto execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. An attacked\ncould potentially exploit this to execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. An attacker could potentially exploit this to cause a denial of\nservice via application crash or execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5597)\n\nCody Crews discovered a way to append an iframe in to an embedded PDF\nobject displayed with PDF.js. An attacked could potentially exploit this\nto read local files, leading to information disclosure. (CVE-2013-5598)\n\nMultiple use-after-free flaws were discovered in Firefox. An attacker\ncould potentially exploit these to cause a denial of service via\napplication crash or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5599, CVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. An attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. An attacker could potentially exploit this to cause\na denial of service via application crash or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.04.1"}],"saucy":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.10.1"}],"quantal":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.10.1"}],"raring":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5592","CVE-2013-5593","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5598","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603","CVE-2013-5604"]}]},{"id":"CVE-2013-5598","published":"2013-10-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does\nnot properly handle the appending of an IFRAME element, which allows remote\nattackers to read arbitrary files or execute arbitrary JavaScript code with\nchrome privileges by using this element within an embedded PDF object.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-99.html","https://ubuntu.com/security/notices/USN-2009-1","https://www.cve.org/CVERecord?id=CVE-2013-5598"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0+build3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0+build3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0+build3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0+build3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2009-1"],"notices":[{"id":"USN-2009-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245414"],"published":"2013-10-29T19:18:10.283611","description":"Multiple memory safety issues were discovered in Firefox. If a user were\ntricked in to opening a specially crafted page, an attacker could possibly\nexploit these to cause a denial of service via application crash, or\npotentially execute arbitrary code with the privileges of the user\ninvoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,\nCVE-2013-5592)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. An attacker could potentially exploit this to conduct\nURL spoofing or clickjacking attacks (CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. An attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. When combined\nwith other vulnerabilities, an attacked could possibly exploit this\nto execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. An attacked\ncould potentially exploit this to execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. An attacker could potentially exploit this to cause a denial of\nservice via application crash or execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5597)\n\nCody Crews discovered a way to append an iframe in to an embedded PDF\nobject displayed with PDF.js. An attacked could potentially exploit this\nto read local files, leading to information disclosure. (CVE-2013-5598)\n\nMultiple use-after-free flaws were discovered in Firefox. An attacker\ncould potentially exploit these to cause a denial of service via\napplication crash or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5599, CVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. An attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. An attacker could potentially exploit this to cause\na denial of service via application crash or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.04.1"}],"saucy":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.10.1"}],"quantal":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.10.1"}],"raring":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5592","CVE-2013-5593","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5598","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603","CVE-2013-5604"]}]},{"id":"CVE-2013-5597","published":"2013-10-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the nsDocLoader::doStopDocumentLoad\nfunction in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10\nand 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before\n17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute\narbitrary code or cause a denial of service (heap memory corruption) via\nvectors involving a state-change event during an update of the offline\ncache.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-98.html","https://ubuntu.com/security/notices/USN-2009-1","https://ubuntu.com/security/notices/USN-2010-1","https://www.cve.org/CVERecord?id=CVE-2013-5597"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0+build3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0+build3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0+build3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0+build3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.1.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2010-1","USN-2009-1"],"notices":[{"id":"USN-2010-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245422"],"published":"2013-10-31T12:48:46.252086","description":"Multiple memory safety issues were discovered in Thunderbird. If a user\nwere tricked in to opening a specially crafted message with scripting\nenabled, an attacker could possibly exploit these to cause a denial of\nservice via application crash, or potentially execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-1739,\nCVE-2013-5590, CVE-2013-5591)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. If a user had scripting enabled, an attacker could potentially\nexploit this to conduct URL spoofing or clickjacking attacks.\n(CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. If a user had scripting enabled, an attacker could\npotentially exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. If a user had\nenabled scripting, when combined with other vulnerabilities an attacker\ncould possibly exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. If a user had\nscripting enabled, an attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Thunderbird.\n(CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. If a user had scripting enabled, an attacker could potentially\nexploit this to cause a denial of service via application crash or\nexecute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5597)\n\nMultiple use-after-free flaws were discovered in Thunderbird. If a user\nhad scripting enabled, an attacker could potentially exploit these to\ncause a denial of service via application crash or execute arbitrary code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-5599,\nCVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. If a user had scripting enabled, an\nattacker could potentially exploit this to cause a denial of service\nvia application crash or execute arbitrary code with the privileges of\nthe user invoking Thunderbird. (CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. If a user had scripting enabled, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5593","CVE-2013-5604","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603"]},{"id":"USN-2009-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245414"],"published":"2013-10-29T19:18:10.283611","description":"Multiple memory safety issues were discovered in Firefox. If a user were\ntricked in to opening a specially crafted page, an attacker could possibly\nexploit these to cause a denial of service via application crash, or\npotentially execute arbitrary code with the privileges of the user\ninvoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,\nCVE-2013-5592)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. An attacker could potentially exploit this to conduct\nURL spoofing or clickjacking attacks (CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. An attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. When combined\nwith other vulnerabilities, an attacked could possibly exploit this\nto execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. An attacked\ncould potentially exploit this to execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. An attacker could potentially exploit this to cause a denial of\nservice via application crash or execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5597)\n\nCody Crews discovered a way to append an iframe in to an embedded PDF\nobject displayed with PDF.js. An attacked could potentially exploit this\nto read local files, leading to information disclosure. (CVE-2013-5598)\n\nMultiple use-after-free flaws were discovered in Firefox. An attacker\ncould potentially exploit these to cause a denial of service via\napplication crash or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5599, CVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. An attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. An attacker could potentially exploit this to cause\na denial of service via application crash or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.04.1"}],"saucy":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.10.1"}],"quantal":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.10.1"}],"raring":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5592","CVE-2013-5593","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5598","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603","CVE-2013-5604"]}]},{"id":"CVE-2013-5596","published":"2013-10-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe cycle collection (CC) implementation in Mozilla Firefox before 25.0,\nFirefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before\n2.22 does not properly determine the thread for release of an image object,\nwhich allows remote attackers to execute arbitrary code or cause a denial\nof service (race condition and application crash) via a large HTML document\ncontaining IMG elements, as demonstrated by the Never-Ending Reddit on\nreddit.com.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-97.html","https://ubuntu.com/security/notices/USN-2009-1","https://ubuntu.com/security/notices/USN-2010-1","https://www.cve.org/CVERecord?id=CVE-2013-5596"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0+build3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0+build3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0+build3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0+build3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.1.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2010-1","USN-2009-1"],"notices":[{"id":"USN-2010-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245422"],"published":"2013-10-31T12:48:46.252086","description":"Multiple memory safety issues were discovered in Thunderbird. If a user\nwere tricked in to opening a specially crafted message with scripting\nenabled, an attacker could possibly exploit these to cause a denial of\nservice via application crash, or potentially execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-1739,\nCVE-2013-5590, CVE-2013-5591)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. If a user had scripting enabled, an attacker could potentially\nexploit this to conduct URL spoofing or clickjacking attacks.\n(CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. If a user had scripting enabled, an attacker could\npotentially exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. If a user had\nenabled scripting, when combined with other vulnerabilities an attacker\ncould possibly exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. If a user had\nscripting enabled, an attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Thunderbird.\n(CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. If a user had scripting enabled, an attacker could potentially\nexploit this to cause a denial of service via application crash or\nexecute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5597)\n\nMultiple use-after-free flaws were discovered in Thunderbird. If a user\nhad scripting enabled, an attacker could potentially exploit these to\ncause a denial of service via application crash or execute arbitrary code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-5599,\nCVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. If a user had scripting enabled, an\nattacker could potentially exploit this to cause a denial of service\nvia application crash or execute arbitrary code with the privileges of\nthe user invoking Thunderbird. (CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. If a user had scripting enabled, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5593","CVE-2013-5604","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603"]},{"id":"USN-2009-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245414"],"published":"2013-10-29T19:18:10.283611","description":"Multiple memory safety issues were discovered in Firefox. If a user were\ntricked in to opening a specially crafted page, an attacker could possibly\nexploit these to cause a denial of service via application crash, or\npotentially execute arbitrary code with the privileges of the user\ninvoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,\nCVE-2013-5592)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. An attacker could potentially exploit this to conduct\nURL spoofing or clickjacking attacks (CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. An attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. When combined\nwith other vulnerabilities, an attacked could possibly exploit this\nto execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. An attacked\ncould potentially exploit this to execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. An attacker could potentially exploit this to cause a denial of\nservice via application crash or execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5597)\n\nCody Crews discovered a way to append an iframe in to an embedded PDF\nobject displayed with PDF.js. An attacked could potentially exploit this\nto read local files, leading to information disclosure. (CVE-2013-5598)\n\nMultiple use-after-free flaws were discovered in Firefox. An attacker\ncould potentially exploit these to cause a denial of service via\napplication crash or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5599, CVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. An attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. An attacker could potentially exploit this to cause\na denial of service via application crash or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.04.1"}],"saucy":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.10.1"}],"quantal":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.10.1"}],"raring":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5592","CVE-2013-5593","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5598","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603","CVE-2013-5604"]}]},{"id":"CVE-2013-5595","published":"2013-10-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe JavaScript engine in Mozilla Firefox before 25.0, Firefox ESR 17.x\nbefore 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird\nESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly\nallocate memory for unspecified functions, which allows remote attackers to\nconduct buffer overflow attacks via a crafted web page.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-96.html","https://ubuntu.com/security/notices/USN-2009-1","https://ubuntu.com/security/notices/USN-2010-1","https://www.cve.org/CVERecord?id=CVE-2013-5595"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0+build3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0+build3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0+build3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0+build3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.1.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2010-1","USN-2009-1"],"notices":[{"id":"USN-2010-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245422"],"published":"2013-10-31T12:48:46.252086","description":"Multiple memory safety issues were discovered in Thunderbird. If a user\nwere tricked in to opening a specially crafted message with scripting\nenabled, an attacker could possibly exploit these to cause a denial of\nservice via application crash, or potentially execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-1739,\nCVE-2013-5590, CVE-2013-5591)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. If a user had scripting enabled, an attacker could potentially\nexploit this to conduct URL spoofing or clickjacking attacks.\n(CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. If a user had scripting enabled, an attacker could\npotentially exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. If a user had\nenabled scripting, when combined with other vulnerabilities an attacker\ncould possibly exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. If a user had\nscripting enabled, an attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Thunderbird.\n(CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. If a user had scripting enabled, an attacker could potentially\nexploit this to cause a denial of service via application crash or\nexecute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5597)\n\nMultiple use-after-free flaws were discovered in Thunderbird. If a user\nhad scripting enabled, an attacker could potentially exploit these to\ncause a denial of service via application crash or execute arbitrary code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-5599,\nCVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. If a user had scripting enabled, an\nattacker could potentially exploit this to cause a denial of service\nvia application crash or execute arbitrary code with the privileges of\nthe user invoking Thunderbird. (CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. If a user had scripting enabled, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5593","CVE-2013-5604","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603"]},{"id":"USN-2009-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245414"],"published":"2013-10-29T19:18:10.283611","description":"Multiple memory safety issues were discovered in Firefox. If a user were\ntricked in to opening a specially crafted page, an attacker could possibly\nexploit these to cause a denial of service via application crash, or\npotentially execute arbitrary code with the privileges of the user\ninvoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,\nCVE-2013-5592)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. An attacker could potentially exploit this to conduct\nURL spoofing or clickjacking attacks (CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. An attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. When combined\nwith other vulnerabilities, an attacked could possibly exploit this\nto execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. An attacked\ncould potentially exploit this to execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. An attacker could potentially exploit this to cause a denial of\nservice via application crash or execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5597)\n\nCody Crews discovered a way to append an iframe in to an embedded PDF\nobject displayed with PDF.js. An attacked could potentially exploit this\nto read local files, leading to information disclosure. (CVE-2013-5598)\n\nMultiple use-after-free flaws were discovered in Firefox. An attacker\ncould potentially exploit these to cause a denial of service via\napplication crash or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5599, CVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. An attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. An attacker could potentially exploit this to cause\na denial of service via application crash or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.04.1"}],"saucy":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.10.1"}],"quantal":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.10.1"}],"raring":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5592","CVE-2013-5593","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5598","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603","CVE-2013-5604"]}]},{"id":"CVE-2013-5593","published":"2013-10-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe SELECT element implementation in Mozilla Firefox before 25.0, Firefox\nESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22\ndoes not properly restrict the nature or placement of HTML within a\ndropdown menu, which allows remote attackers to spoof the address bar or\nconduct clickjacking attacks via vectors that trigger navigation off of a\npage containing this element.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-94.html","https://ubuntu.com/security/notices/USN-2009-1","https://ubuntu.com/security/notices/USN-2010-1","https://www.cve.org/CVERecord?id=CVE-2013-5593"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0+build3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0+build3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0+build3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0+build3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.1.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2010-1","USN-2009-1"],"notices":[{"id":"USN-2010-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245422"],"published":"2013-10-31T12:48:46.252086","description":"Multiple memory safety issues were discovered in Thunderbird. If a user\nwere tricked in to opening a specially crafted message with scripting\nenabled, an attacker could possibly exploit these to cause a denial of\nservice via application crash, or potentially execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-1739,\nCVE-2013-5590, CVE-2013-5591)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. If a user had scripting enabled, an attacker could potentially\nexploit this to conduct URL spoofing or clickjacking attacks.\n(CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. If a user had scripting enabled, an attacker could\npotentially exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. If a user had\nenabled scripting, when combined with other vulnerabilities an attacker\ncould possibly exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. If a user had\nscripting enabled, an attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Thunderbird.\n(CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. If a user had scripting enabled, an attacker could potentially\nexploit this to cause a denial of service via application crash or\nexecute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5597)\n\nMultiple use-after-free flaws were discovered in Thunderbird. If a user\nhad scripting enabled, an attacker could potentially exploit these to\ncause a denial of service via application crash or execute arbitrary code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-5599,\nCVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. If a user had scripting enabled, an\nattacker could potentially exploit this to cause a denial of service\nvia application crash or execute arbitrary code with the privileges of\nthe user invoking Thunderbird. (CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. If a user had scripting enabled, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5593","CVE-2013-5604","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603"]},{"id":"USN-2009-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245414"],"published":"2013-10-29T19:18:10.283611","description":"Multiple memory safety issues were discovered in Firefox. If a user were\ntricked in to opening a specially crafted page, an attacker could possibly\nexploit these to cause a denial of service via application crash, or\npotentially execute arbitrary code with the privileges of the user\ninvoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,\nCVE-2013-5592)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. An attacker could potentially exploit this to conduct\nURL spoofing or clickjacking attacks (CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. An attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. When combined\nwith other vulnerabilities, an attacked could possibly exploit this\nto execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. An attacked\ncould potentially exploit this to execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. An attacker could potentially exploit this to cause a denial of\nservice via application crash or execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5597)\n\nCody Crews discovered a way to append an iframe in to an embedded PDF\nobject displayed with PDF.js. An attacked could potentially exploit this\nto read local files, leading to information disclosure. (CVE-2013-5598)\n\nMultiple use-after-free flaws were discovered in Firefox. An attacker\ncould potentially exploit these to cause a denial of service via\napplication crash or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5599, CVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. An attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. An attacker could potentially exploit this to cause\na denial of service via application crash or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.04.1"}],"saucy":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.10.1"}],"quantal":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.10.1"}],"raring":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5592","CVE-2013-5593","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5598","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603","CVE-2013-5604"]}]},{"id":"CVE-2013-5592","published":"2013-10-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox before 25.0 allow remote attackers to cause a denial of service\n(memory corruption and application crash) or possibly execute arbitrary\ncode via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-93.html","https://ubuntu.com/security/notices/USN-2009-1","https://www.cve.org/CVERecord?id=CVE-2013-5592"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0+build3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0+build3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0+build3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0+build3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2009-1"],"notices":[{"id":"USN-2009-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245414"],"published":"2013-10-29T19:18:10.283611","description":"Multiple memory safety issues were discovered in Firefox. If a user were\ntricked in to opening a specially crafted page, an attacker could possibly\nexploit these to cause a denial of service via application crash, or\npotentially execute arbitrary code with the privileges of the user\ninvoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,\nCVE-2013-5592)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. An attacker could potentially exploit this to conduct\nURL spoofing or clickjacking attacks (CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. An attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. When combined\nwith other vulnerabilities, an attacked could possibly exploit this\nto execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. An attacked\ncould potentially exploit this to execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. An attacker could potentially exploit this to cause a denial of\nservice via application crash or execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5597)\n\nCody Crews discovered a way to append an iframe in to an embedded PDF\nobject displayed with PDF.js. An attacked could potentially exploit this\nto read local files, leading to information disclosure. (CVE-2013-5598)\n\nMultiple use-after-free flaws were discovered in Firefox. An attacker\ncould potentially exploit these to cause a denial of service via\napplication crash or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5599, CVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. An attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. An attacker could potentially exploit this to cause\na denial of service via application crash or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.04.1"}],"saucy":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.10.1"}],"quantal":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.10.1"}],"raring":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5592","CVE-2013-5593","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5598","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603","CVE-2013-5604"]}]},{"id":"CVE-2013-5591","published":"2013-10-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the browser engine in Mozilla Firefox before\n25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey\nbefore 2.22 allows remote attackers to cause a denial of service (memory\ncorruption and application crash) or possibly execute arbitrary code via\nunknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-93.html","https://ubuntu.com/security/notices/USN-2009-1","https://ubuntu.com/security/notices/USN-2010-1","https://www.cve.org/CVERecord?id=CVE-2013-5591"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0+build3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0+build3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0+build3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0+build3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.1.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2010-1","USN-2009-1"],"notices":[{"id":"USN-2010-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245422"],"published":"2013-10-31T12:48:46.252086","description":"Multiple memory safety issues were discovered in Thunderbird. If a user\nwere tricked in to opening a specially crafted message with scripting\nenabled, an attacker could possibly exploit these to cause a denial of\nservice via application crash, or potentially execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-1739,\nCVE-2013-5590, CVE-2013-5591)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. If a user had scripting enabled, an attacker could potentially\nexploit this to conduct URL spoofing or clickjacking attacks.\n(CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. If a user had scripting enabled, an attacker could\npotentially exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. If a user had\nenabled scripting, when combined with other vulnerabilities an attacker\ncould possibly exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. If a user had\nscripting enabled, an attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Thunderbird.\n(CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. If a user had scripting enabled, an attacker could potentially\nexploit this to cause a denial of service via application crash or\nexecute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5597)\n\nMultiple use-after-free flaws were discovered in Thunderbird. If a user\nhad scripting enabled, an attacker could potentially exploit these to\ncause a denial of service via application crash or execute arbitrary code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-5599,\nCVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. If a user had scripting enabled, an\nattacker could potentially exploit this to cause a denial of service\nvia application crash or execute arbitrary code with the privileges of\nthe user invoking Thunderbird. (CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. If a user had scripting enabled, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5593","CVE-2013-5604","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603"]},{"id":"USN-2009-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245414"],"published":"2013-10-29T19:18:10.283611","description":"Multiple memory safety issues were discovered in Firefox. If a user were\ntricked in to opening a specially crafted page, an attacker could possibly\nexploit these to cause a denial of service via application crash, or\npotentially execute arbitrary code with the privileges of the user\ninvoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,\nCVE-2013-5592)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. An attacker could potentially exploit this to conduct\nURL spoofing or clickjacking attacks (CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. An attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. When combined\nwith other vulnerabilities, an attacked could possibly exploit this\nto execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. An attacked\ncould potentially exploit this to execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. An attacker could potentially exploit this to cause a denial of\nservice via application crash or execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5597)\n\nCody Crews discovered a way to append an iframe in to an embedded PDF\nobject displayed with PDF.js. An attacked could potentially exploit this\nto read local files, leading to information disclosure. (CVE-2013-5598)\n\nMultiple use-after-free flaws were discovered in Firefox. An attacker\ncould potentially exploit these to cause a denial of service via\napplication crash or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5599, CVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. An attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. An attacker could potentially exploit this to cause\na denial of service via application crash or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.04.1"}],"saucy":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.10.1"}],"quantal":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.10.1"}],"raring":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5592","CVE-2013-5593","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5598","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603","CVE-2013-5604"]}]},{"id":"CVE-2013-5590","published":"2013-10-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1,\nThunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey\nbefore 2.22 allow remote attackers to cause a denial of service (memory\ncorruption and application crash) or possibly execute arbitrary code via\nunknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-93.html","https://ubuntu.com/security/notices/USN-2009-1","https://ubuntu.com/security/notices/USN-2010-1","https://www.cve.org/CVERecord?id=CVE-2013-5590"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0+build3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0+build3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0+build3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0+build3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1:24.1.0+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:24.1.0+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.1.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-2010-1","USN-2009-1"],"notices":[{"id":"USN-2010-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245422"],"published":"2013-10-31T12:48:46.252086","description":"Multiple memory safety issues were discovered in Thunderbird. If a user\nwere tricked in to opening a specially crafted message with scripting\nenabled, an attacker could possibly exploit these to cause a denial of\nservice via application crash, or potentially execute arbitrary code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-1739,\nCVE-2013-5590, CVE-2013-5591)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. If a user had scripting enabled, an attacker could potentially\nexploit this to conduct URL spoofing or clickjacking attacks.\n(CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. If a user had scripting enabled, an attacker could\npotentially exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. If a user had\nenabled scripting, when combined with other vulnerabilities an attacker\ncould possibly exploit this to execute arbitrary code with the privileges\nof the user invoking Thunderbird. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. If a user had\nscripting enabled, an attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Thunderbird.\n(CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. If a user had scripting enabled, an attacker could potentially\nexploit this to cause a denial of service via application crash or\nexecute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5597)\n\nMultiple use-after-free flaws were discovered in Thunderbird. If a user\nhad scripting enabled, an attacker could potentially exploit these to\ncause a denial of service via application crash or execute arbitrary code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-5599,\nCVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. If a user had scripting enabled, an\nattacker could potentially exploit this to cause a denial of service\nvia application crash or execute arbitrary code with the privileges of\nthe user invoking Thunderbird. (CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. If a user had scripting enabled, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash or execute arbitrary code with the privileges of the user invoking\nThunderbird. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.0+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.0+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5593","CVE-2013-5604","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603"]},{"id":"USN-2009-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1245414"],"published":"2013-10-29T19:18:10.283611","description":"Multiple memory safety issues were discovered in Firefox. If a user were\ntricked in to opening a specially crafted page, an attacker could possibly\nexploit these to cause a denial of service via application crash, or\npotentially execute arbitrary code with the privileges of the user\ninvoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,\nCVE-2013-5592)\n\nJordi Chancel discovered that HTML select elements could display arbitrary\ncontent. An attacker could potentially exploit this to conduct\nURL spoofing or clickjacking attacks (CVE-2013-5593)\n\nAbhishek Arya discovered a crash when processing XSLT data in some\ncircumstances. An attacker could potentially exploit this to execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5604)\n\nDan Gohman discovered a flaw in the Javascript engine. When combined\nwith other vulnerabilities, an attacked could possibly exploit this\nto execute arbitrary code with the privileges of the user invoking\nFirefox. (CVE-2013-5595)\n\nEzra Pool discovered a crash on extremely large pages. An attacked\ncould potentially exploit this to execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5596)\n\nByoungyoung Lee discovered a use-after-free when updating the offline\ncache. An attacker could potentially exploit this to cause a denial of\nservice via application crash or execute arbitrary code with the\nprivileges of the user invoking Firefox. (CVE-2013-5597)\n\nCody Crews discovered a way to append an iframe in to an embedded PDF\nobject displayed with PDF.js. An attacked could potentially exploit this\nto read local files, leading to information disclosure. (CVE-2013-5598)\n\nMultiple use-after-free flaws were discovered in Firefox. An attacker\ncould potentially exploit these to cause a denial of service via\napplication crash or execute arbitrary code with the privileges of the\nuser invoking Firefox. (CVE-2013-5599, CVE-2013-5600, CVE-2013-5601)\n\nA memory corruption flaw was discovered in the Javascript engine when\nusing workers with direct proxies. An attacker could potentially exploit\nthis to cause a denial of service via application crash or execute\narbitrary code with the privileges of the user invoking Firefox.\n(CVE-2013-5602)\n\nAbhishek Arya discovered a use-after-free when interacting with HTML\ndocument templates. An attacker could potentially exploit this to cause\na denial of service via application crash or execute arbitrary code with\nthe privileges of the user invoking Firefox. (CVE-2013-5603)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.04.1"}],"saucy":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.10.1"}],"quantal":[{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.12.10.1"}],"raring":[{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0+build3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0+build3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-5590","CVE-2013-5591","CVE-2013-5592","CVE-2013-5593","CVE-2013-5595","CVE-2013-5596","CVE-2013-5597","CVE-2013-5598","CVE-2013-5599","CVE-2013-5600","CVE-2013-5601","CVE-2013-5602","CVE-2013-5603","CVE-2013-5604"]}]}],"offset":66720,"limit":20,"total_results":79316}