CVE-2013-0796

Description

The WebGL subsystem in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 on Linux does not properly interact with Mesa drivers, which allows remote attackers to execute arbitrary code or cause a denial of service (free of unallocated memory) via unspecified vectors.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.876

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Mozilla Firefox (x64) 19.0.2Windows
Multiple vulnerabilities affected in Mozilla Firefox ESR (x64) 17.0.4Windows
Multiple vulnerabilities affected in Mozilla Firefox ESR 17.0.4Windows
Multiple vulnerabilities affected in Mozilla Thunderbird 17.0.4Windows
Multiple vulnerabilities affected in Mozilla Thunderbird ESR 17.0.4Windows
Multiple vulnerabilities affected in Mozilla_Firefox 19.0.2Windows
Multiple vulnerabilities affected in SeaMonkey 2.9.1Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 17.0.4Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird ESR 17.0.4Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 19.0.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 19.0.2Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 19.0.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 19.0.2Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-343016Mozilla Firefox (x64) (132.0.2)
PATCH-310844Mozilla Firefox ESR (x64) (60.9.0)
PATCH-310843Mozilla Firefox ESR (60.9.0)
PATCH-315938Mozilla Thunderbird (68.12.0)
PATCH-343015Mozilla Firefox (132.0.2)
PATCH-341197SeaMonkey (2.53.19)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234