CVE-2013-0757

Exp

The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not prevent modifications to the prototype of an object, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by referencing Object.prototype.__proto__ in a crafted HTML document.

Published: 2013-01-13 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2013-0757 is rated High Exploit Risk (81.8/100): CVSS Critical severity, with high exploitation likelihood (EPSS 74.57%, 99th percentile). Core evidence: 3 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2013-0757

EDB-ID Source Kind Published Link
41684 exploit_db edb 2014-12-18 Exploit-DB ↗
41683 exploit_db edb 2013-01-08 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2013-0757

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-03-30 81.19% 74.57% -6.62%
2 2025-03-29 74.57% 81.19% +6.62%
3 2025-03-17 74.57%

Full EPSS history (8 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2013-0757

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
9.3 2.0 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
8.6 10.0 [email protected]

Weakness enumeration for CVE-2013-0757

OS Trackers for CVE-2013-0757

vendor priority summary link
gentoo high CVE-2013-0757: 1 GLSA(s) (201309-23), 6 atom(s) (mail-client/thunderbird, mail-client/thunderbird-bin, www-client/firefox, www-client/firefox-bin, www-client/seamonkey, www-client/seamonkey-bin); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2013-0757
redhat critical https://access.redhat.com/security/cve/CVE-2013-0757
suse medium CVE-2013-0757 severity moderate: SUSE including 85 source package names (MozillaFirefox, MozillaFirefox-10.0.12-0.4.1, …), 165 product×package rows across 45 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (45 product lines)): Fixed 134, Known Not Affected 31. https://www.suse.com/security/cve/CVE-2013-0757/
ubuntu medium CVE-2013-0757 medium priority: Ubuntu including 3 source packages (firefox, seamonkey, thunderbird), 24 status rows across 8 suites (hardy, lucid, oneiric, precise, quantal, raring, saucy, upstream): released 15, ignored 5, DNE 4. https://ubuntu.com/security/CVE-2013-0757

Affected software / configurations for CVE-2013-0757

Vendor Product Version Raw CPE
mozilla firefox < 17.0.2 cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozilla firefox < 18.0 cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozilla seamonkey < 2.15 cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
mozilla thunderbird < 17.0.2 cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
mozilla thunderbird_esr < 17.0.2 cpe:2.3:a:mozilla:thunderbird_esr:*:*:*:*:*:*:*:*
opensuse opensuse 11.4 cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
opensuse opensuse 12.1 cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
opensuse opensuse 12.2 cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*
suse linux_enterprise_desktop 10 cpe:2.3:o:suse:linux_enterprise_desktop:10:sp4:*:*:*:*:*:*
suse linux_enterprise_desktop 11 cpe:2.3:o:suse:linux_enterprise_desktop:11:sp2:*:*:*:*:*:*
suse linux_enterprise_server 10 cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:*:*:*:*
suse linux_enterprise_server 11 cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:-:*:*
suse linux_enterprise_server 11 cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:vmware:*:*
suse linux_enterprise_software_development_kit 10 cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp4:*:*:*:*:*:*
suse linux_enterprise_software_development_kit 11 cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp2:*:*:*:*:*:*
canonical ubuntu_linux 10.04 cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
canonical ubuntu_linux 11.10 cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
canonical ubuntu_linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
canonical ubuntu_linux 12.10 cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*

References for CVE-2013-0757

URL Tags
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00006.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00007.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00010.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00017.html Third Party Advisory
http://www.mozilla.org/security/announce/2013/mfsa2013-14.html Vendor Advisory
http://www.ubuntu.com/usn/USN-1681-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-1681-2 Third Party Advisory
http://www.ubuntu.com/usn/USN-1681-4 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=813901 Exploit Issue Tracking Patch Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16939 Third Party Advisory
cvelogic Threat Intelligence