CVE-2013-1674Use After Free in Mozilla Firefox

Severity
9.3CRITICALNVD
EPSS
4.0%
top 11.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateMay 17

Description

Use-after-free vulnerability in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code via vectors involving an onresize event during the playing of a video.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

NVDmozilla/firefox20.0.1+10
NVDmozilla/thunderbird17.0.5+5
NVDmozilla/thunderbird_esr6 versions+5

🔴Vulnerability Details

2
GHSA
GHSA-hq6f-432r-r9gm: Use-after-free vulnerability in Mozilla Firefox before 212022-05-17
CVEList
CVE-2013-1674: Use-after-free vulnerability in Mozilla Firefox before 212013-05-16

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2013-05-14
Ubuntu
Thunderbird vulnerabilities2013-05-14
Red Hat
Mozilla: Use-after-free with video and onresize event (MFSA 2013-46)2013-05-14

💬Community

1
Bugzilla
CVE-2013-1674 Mozilla: Use-after-free with video and onresize event (MFSA 2013-46)2013-05-14
CVE-2013-1674 — Use After Free in Mozilla Firefox | cvebase