4.3
CVSSv2

CVE-2013-1708

Published: 07/08/2013 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 385
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Mozilla Firefox prior to 23.0 and SeaMonkey prior to 2.20 allow remote malicious users to cause a denial of service (application crash) via a crafted WAV file that is not properly handled by the nsCString::CharAt function.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla seamonkey 2.20

mozilla seamonkey 2.0

mozilla seamonkey 2.0.1

mozilla seamonkey 2.0.10

mozilla seamonkey 2.0.4

mozilla seamonkey 2.0.5

mozilla seamonkey 2.0.6

mozilla seamonkey 2.1

mozilla seamonkey 2.10

mozilla seamonkey 2.11

mozilla seamonkey 2.12

mozilla seamonkey 2.12.1

mozilla seamonkey 2.13

mozilla seamonkey 2.13.1

mozilla seamonkey 2.13.2

mozilla seamonkey 2.15

mozilla seamonkey 2.16

mozilla seamonkey 2.17

mozilla seamonkey 2.3

mozilla seamonkey 2.18

mozilla seamonkey

mozilla seamonkey 2.17.1

mozilla seamonkey 2.0.2

mozilla seamonkey 2.0.3

mozilla seamonkey 2.14

mozilla seamonkey 2.15.1

mozilla seamonkey 2.15.2

mozilla seamonkey 2.16.1

mozilla seamonkey 2.16.2

mozilla seamonkey 2.2

mozilla seamonkey 2.3.3

mozilla seamonkey 2.4

mozilla seamonkey 2.5

mozilla seamonkey 2.7

mozilla seamonkey 2.8

mozilla seamonkey 2.9

mozilla seamonkey 2.19

mozilla seamonkey 2.0.11

mozilla seamonkey 2.0.12

mozilla seamonkey 2.0.7

mozilla seamonkey 2.0.8

mozilla seamonkey 2.10.1

mozilla seamonkey 2.4.1

mozilla seamonkey 2.6

mozilla seamonkey 2.9.1

mozilla seamonkey 2.0.13

mozilla seamonkey 2.0.14

mozilla seamonkey 2.0.9

mozilla seamonkey 2.3.1

mozilla seamonkey 2.3.2

mozilla seamonkey 2.6.1

mozilla seamonkey 2.7.1

mozilla seamonkey 2.7.2

mozilla firefox 19.0.2

mozilla firefox 20.0

mozilla firefox

mozilla firefox 20.0.1

mozilla firefox 21.0

mozilla firefox 19.0

mozilla firefox 19.0.1

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
This update provides compatible packages for Firefox 23 ...
Mozilla Foundation Security Advisory 2013-67 Crash during WAV audio file decoding Announced August 6, 2013 Reporter Aki Helin Impact Low Products Firefox, SeaMonkey Fixed in Firef ...
Mozilla Firefox before 230 and SeaMonkey before 220 allow remote attackers to cause a denial of service (application crash) via a crafted WAV file that is not properly handled by the nsCString::CharAt function ...