CVE-2013-0758

CVE-2013-0758

Published · Updated

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 73%
from disclosure to weapon0 days
Published on NVDJan 13
1st PoCJan 8
metasploitJan 8
exploitation probability
73%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
1 product
Red Hat Enterprise Linux 5
none_available: Affected
Fixed
9 products (140 components)
Red Hat Enterprise Linux (v. 5 server) · Red Hat Enterprise Linux Server (v. 6) · Red Hat Enterprise Linux Server Optional (v. 6) · Red Hat Enterprise Linux Desktop (v. 6) · Red Hat Enterprise Linux Workstation (v. 6) · and others 4
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging improper interaction between plugin objects and SVG elements.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.