Lucene search

K
cveMozillaCVE-2013-1715
HistoryAug 07, 2013 - 1:55 a.m.

CVE-2013-1715

2013-08-0701:55:04
mozilla
web.nvd.nist.gov
39
cve-2013-1715
mozilla firefox
untrusted search path
privilege escalation
dll
windows

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

16.2%

Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in Mozilla Firefox before 23.0 on Windows allow local users to gain privileges via a Trojan horse DLL in the default downloads directory. NOTE: this issue exists because of an incomplete fix for CVE-2012-4206.

Affected configurations

Nvd
Node
mozillafirefoxRangeโ‰ค22.0
OR
mozillafirefoxMatch19.0
OR
mozillafirefoxMatch19.0.1
OR
mozillafirefoxMatch19.0.2
OR
mozillafirefoxMatch20.0
OR
mozillafirefoxMatch20.0.1
OR
mozillafirefoxMatch21.0
AND
microsoftwindows
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillafirefox19.0cpe:2.3:a:mozilla:firefox:19.0:*:*:*:*:*:*:*
mozillafirefox19.0.1cpe:2.3:a:mozilla:firefox:19.0.1:*:*:*:*:*:*:*
mozillafirefox19.0.2cpe:2.3:a:mozilla:firefox:19.0.2:*:*:*:*:*:*:*
mozillafirefox20.0cpe:2.3:a:mozilla:firefox:20.0:*:*:*:*:*:*:*
mozillafirefox20.0.1cpe:2.3:a:mozilla:firefox:20.0.1:*:*:*:*:*:*:*
mozillafirefox21.0cpe:2.3:a:mozilla:firefox:21.0:*:*:*:*:*:*:*
microsoftwindows*cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

16.2%