CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
Percentile
94.1%
Use-after-free vulnerability in the
nsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla
Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1,
and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code
or cause a denial of service (heap memory corruption) via vectors involving
HTML document templates.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 12.04 | noarch | firefox | < 25.0+build3-0ubuntu0.12.04.1 | UNKNOWN |
ubuntu | 12.10 | noarch | firefox | < 25.0+build3-0ubuntu0.12.10.1 | UNKNOWN |
ubuntu | 13.04 | noarch | firefox | < 25.0+build3-0ubuntu0.13.04.1 | UNKNOWN |
ubuntu | 13.10 | noarch | firefox | < 25.0+build3-0ubuntu0.13.10.1 | UNKNOWN |
ubuntu | 12.04 | noarch | thunderbird | < 1:24.1.0+build1-0ubuntu0.12.04.1 | UNKNOWN |
ubuntu | 12.10 | noarch | thunderbird | < 1:24.1.0+build1-0ubuntu0.12.10.1 | UNKNOWN |
ubuntu | 13.04 | noarch | thunderbird | < 1:24.1.0+build1-0ubuntu0.13.04.1 | UNKNOWN |
ubuntu | 13.10 | noarch | thunderbird | < 1:24.1.0+build1-0ubuntu0.13.10.1 | UNKNOWN |