6.9
CVSSv2

CVE-2013-1715

Published: 07/08/2013 Updated: 19/09/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in Mozilla Firefox prior to 23.0 on Windows allow local users to gain privileges via a Trojan horse DLL in the default downloads directory. NOTE: this issue exists because of an incomplete fix for CVE-2012-4206.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 19.0

mozilla firefox 19.0.1

mozilla firefox 19.0.2

mozilla firefox 20.0

mozilla firefox 20.0.1

mozilla firefox 21.0

mozilla firefox

Vendor Advisories

Mozilla Foundation Security Advisory 2013-74 Firefox full and stub installer DLL hijacking Announced August 6, 2013 Reporter Robert Kugler, Brian Bondy, Robert Strong Impact High Products Firefox, SeaMonkey Fixed in ...