Lucene search

K
cve[email protected]CVE-2013-1688
HistoryJun 26, 2013 - 3:19 a.m.

CVE-2013-1688

2013-06-2603:19:10
CWE-94
web.nvd.nist.gov
47
mozilla
firefox
profiler
cve-2013-1688
ui rendering
javascript
remote code execution
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

High

EPSS

0.012

Percentile

84.9%

The Profiler implementation in Mozilla Firefox before 22.0 parses untrusted data during UI rendering, which allows user-assisted remote attackers to execute arbitrary JavaScript code via a crafted web site.

Affected configurations

NVD
Node
mozillafirefoxRangeโ‰ค21.0
OR
mozillafirefoxMatch19.0
OR
mozillafirefoxMatch19.0.1
OR
mozillafirefoxMatch19.0.2
OR
mozillafirefoxMatch20.0
OR
mozillafirefoxMatch20.0.1
VendorProductVersionCPE
mozillafirefox19.0.2cpe:/a:mozilla:firefox:19.0.2:::
mozillafirefox20.0cpe:/a:mozilla:firefox:20.0:::
mozillafirefoxcpe:/a:mozilla:firefox::::
mozillafirefox19.0cpe:/a:mozilla:firefox:19.0:::
mozillafirefox19.0.1cpe:/a:mozilla:firefox:19.0.1:::
mozillafirefox20.0.1cpe:/a:mozilla:firefox:20.0.1:::

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

High

EPSS

0.012

Percentile

84.9%