Vulnerability record · CVE-2013-0758 · published 13 January 2013
CVE-2013-0758: Firefox, Thunderbird and SeaMonkey plugin/SVG chrome privilege code injection
Mozilla · Firefox
Mozilla Firefox, Thunderbird and SeaMonkey fail to properly handle the interaction between plugin objects and SVG elements, allowing remote attackers to execute arbitrary JavaScript with chrome (browser-internal) privileges. Because chrome privileges bypass the browser's security boundaries, a successful attack can lead to full compromise of the affected client. The flaw affects Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15.
Description
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging improper interaction between plugin objects and SVG elements.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows remote code execution with chrome privileges and has a very high EPSS score, but it is an old vulnerability with patches available and no KEV listing or confirmed in-the-wild exploitation in the record.
What it is
Mozilla Firefox, Thunderbird and SeaMonkey fail to properly handle the interaction between plugin objects and SVG elements, allowing remote attackers to execute arbitrary JavaScript with chrome (browser-internal) privileges. Because chrome privileges bypass the browser's security boundaries, a successful attack can lead to full compromise of the affected client. The flaw affects Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15.
Impact
An attacker gains arbitrary JavaScript execution in the browser's privileged chrome context, which can be used to run code with the user's rights, read or modify local data, and potentially install malware or take over the host.
Attack surface
The vulnerability is network-reachable (AV:N) and requires no authentication, but the CVSS vector indicates medium access complexity (AC:M), consistent with the need to get a victim to load crafted content involving plugin objects and SVG elements. Some form of user interaction, such as visiting a malicious page or opening crafted content, is implied by the browser and mail client attack path.
Exploitation
CVE-2013-0758 is not listed in CISA KEV, but EPSS gives it a 30-day exploitation probability of 0.73364 (99.4th percentile), indicating high predicted likelihood of exploitation activity. Reference tags are vendor and third-party advisories only, with no public exploit or in-the-wild reporting tags supplied.
What to do
- Upgrade Firefox to 18.0 or later, Firefox ESR to 10.0.12 or 17.0.2 or later, Thunderbird to 17.0.2 or later, Thunderbird ESR to 10.0.12 or 17.0.2 or later, and SeaMonkey to 2.15 or later.
- Apply the vendor and distribution updates referenced in the Mozilla MFSA 2013-15 advisory and the Red Hat, openSUSE and Ubuntu security notices.
- If immediate patching is not possible, disable or restrict untrusted plugins and limit browsing and mail rendering of untrusted content.
- Retire or isolate end-of-life browser and mail client versions that cannot be updated to the fixed releases.
Detection
- Monitor for browser or mail client crashes and abnormal child process creation originating from Firefox, Thunderbird or SeaMonkey.
- Hunt for unexpected script or executable activity spawned by browser or mail client processes on endpoints running the affected versions.
- Review proxy and web logs for delivery of pages combining plugin object and SVG content to vulnerable clients, where such telemetry exists.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-0758 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-0758), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.