CVE-2013-1054: Canonical Ubuntu Linux
Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.
The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the extension entirely.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 15.04 only
- Canonical Unity-Firefox-Extension: before 3.0.0\+14.04.20140416-0ubuntu1.14.04.1 (fixed in 3.0.0\+14.04.20140416-0ubuntu1.14.04.1)
Published 2021-04-07. Last modified 2026-06-16.