V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2013-6671
DEB
Critical

The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMon…

CVSS
9.8
Critical
EPSS
0.11
p95
Published
2013-01-01
Updated
2013-01-01
Description

The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements.

Tags · CWE
Pre-auth
CWE-94
CAPEC-35
CAPEC-77
CAPEC-242
Affected products
Enterprise_linux_desktopEnterprise_linux_eusEnterprise_linux_serverEnterprise_linux_server_ausEnterprise_linux_server_eusEnterprise_linux_server_tusEnterprise_linux_workstation
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2013-01-01
Published
2013-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.111 · p95
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-35 · CWE-94
└ via CAPEC-35 · CWE-94
└ via CAPEC-35 · CWE-94
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
firefoxTracked
firefoxTracked
iceapeTracked
iceapeTracked
iceapeTracked
icedoveTracked
icedoveTracked
iceweaselTracked
iceweaselTracked
thunderbirdTracked
thunderbirdTracked
enterprise_linux_desktop*Tracked
enterprise_linux_eus*Tracked
enterprise_linux_server*Tracked
enterprise_linux_server_aus*Tracked
enterprise_linux_server_eus*Tracked
enterprise_linux_server_tus*Tracked
enterprise_linux_workstation*Tracked
fedora*Tracked
firefox*Tracked
Showing first 20 of 27
Source databases
DEB
CVE
RED