Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not ensure that initialization occurs for JavaScript objects with compartments, which allows remote attackers to execute arbitrary code by leveraging incorrect scope handling.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
History
No history.
Information
Published : 2013-09-18 10:08
Updated : 2025-04-11 00:51
NVD link : CVE-2013-1725
Mitre link : CVE-2013-1725
CVE.ORG link : CVE-2013-1725
JSON object : View
Products Affected
mozilla
- thunderbird
- thunderbird_esr
- seamonkey
- firefox
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer