← All CVEs

CVE-2013-5618

critical · 9.8

Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code by triggering improper garbage collection.

9.8
CVSS
10.4%
EPSS (exploit prob.)
96th
EPSS percentile
2013-12-11
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-416

Affected products

VendorProductAffected versions
mozillafirefox< 26.0
mozillafirefox>= 24.0, < 24.2
mozillaseamonkey< 2.23
mozillathunderbird< 24.2
fedoraprojectfedora18
fedoraprojectfedora19
fedoraprojectfedora20
susesuse_linux_enterprise_software_development_kit11.0
opensuseopensuse12.2
opensuseopensuse12.3
opensuseopensuse13.1
susesuse_linux_enterprise_desktop11
susesuse_linux_enterprise_server11
susesuse_linux_enterprise_server11
canonicalubuntu_linux12.04
canonicalubuntu_linux12.10
canonicalubuntu_linux13.04
canonicalubuntu_linux13.10
redhatenterprise_linux_desktop5.0
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_eus6.5
redhatenterprise_linux_server5.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_server_aus6.5
redhatenterprise_linux_server_eus6.5
redhatenterprise_linux_server_tus6.5
redhatenterprise_linux_workstation5.0
redhatenterprise_linux_workstation6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-5618