CVE-2013-0758
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging improper interaction between plugin objects and SVG elements.
- Affected products
- Centos, Firefox Esr, Firefox, Red Hat, Seamonkey, Suse, Thunderbird, Thunderbird Esr
- Mozilla Firefox
- < 18.0, 10.0.12, 17.0.2
- Mozilla Seamonkey
- < 2.15
- Mozilla Thunderbird
- < 17.0.2
- Mozilla Thunderbird Esr
- < 10.0.12, 17.0.2
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 73.4% (99th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2013-01-13
CVE-2013-0758 at NVD
5 known exploits for CVE-2013-0758
Proof-of-concept code and exploit modules indexed by Sploitus
Mozilla Firefox < 17.0.1 - Flash Privileged Code Injection Exploit
GIT 1.8.5.6 / 1.9.5 / 2.0.5 / 2.1.4/ 2.2.1 & Mercurial < 3.2.3 - Exploit
GIT 1.8.5.6/1.9.5/2.0.5/2.1.4/2.2.1 & Mercurial < 3.2.3 - Multiple Vulnerabilities (Metasploit)
Firefox 17.0.1 Flash Privileged Code Injection
Mozilla Firefox < 17.0.1 - Flash Privileged Code Injection (Metasploit)