7.2
CVSSv2

CVE-2013-1707

Published: 07/08/2013 Updated: 19/09/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox prior to 23.0, Firefox ESR 17.x prior to 17.0.8, Thunderbird prior to 17.0.8, and Thunderbird ESR 17.x prior to 17.0.8 allows local users to gain privileges via a long pathname on the command line to the Mozilla Maintenance Service.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla thunderbird 17.0.1

mozilla thunderbird 17.0.3

mozilla thunderbird

mozilla thunderbird 17.0.6

mozilla thunderbird 17.0.4

mozilla thunderbird 17.0.5

mozilla thunderbird 17.0.2

mozilla thunderbird 17.0

mozilla thunderbird esr 17.0.1

mozilla thunderbird esr 17.0.2

mozilla thunderbird esr 17.0.3

mozilla thunderbird esr 17.0.6

mozilla thunderbird esr 17.0.4

mozilla thunderbird esr 17.0.5

mozilla thunderbird esr 17.0.7

mozilla thunderbird esr 17.0

mozilla firefox 19.0.1

mozilla firefox 19.0.2

mozilla firefox 21.0

mozilla firefox 20.0

mozilla firefox 20.0.1

mozilla firefox

mozilla firefox 19.0

mozilla firefox esr 17.0.1

mozilla firefox esr 17.0

mozilla firefox esr 17.0.5

mozilla firefox esr 17.0.6

mozilla firefox esr 17.0.3

mozilla firefox esr 17.0.4

mozilla firefox esr 17.0.7

mozilla firefox esr 17.0.2

Vendor Advisories

Mozilla Foundation Security Advisory 2013-66 Buffer overflow in Mozilla Maintenance Service and Mozilla Updater Announced August 6, 2013 Reporter Seb Patane Impact High Products Firefox, Firefox ESR, SeaMonkey, Thunderbird, ...