CVE-2013-5618
critical · 9.8Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code by triggering improper garbage collection.
9.8
CVSS
10.4%
EPSS (exploit prob.)
96th
EPSS percentile
2013-12-11
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-416
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| mozilla | firefox | < 26.0 |
| mozilla | firefox | >= 24.0, < 24.2 |
| mozilla | seamonkey | < 2.23 |
| mozilla | thunderbird | < 24.2 |
| fedoraproject | fedora | 18 |
| fedoraproject | fedora | 19 |
| fedoraproject | fedora | 20 |
| suse | suse_linux_enterprise_software_development_kit | 11.0 |
| opensuse | opensuse | 12.2 |
| opensuse | opensuse | 12.3 |
| opensuse | opensuse | 13.1 |
| suse | suse_linux_enterprise_desktop | 11 |
| suse | suse_linux_enterprise_server | 11 |
| suse | suse_linux_enterprise_server | 11 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 12.10 |
| canonical | ubuntu_linux | 13.04 |
| canonical | ubuntu_linux | 13.10 |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_eus | 6.5 |
| redhat | enterprise_linux_server | 5.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server_aus | 6.5 |
| redhat | enterprise_linux_server_eus | 6.5 |
| redhat | enterprise_linux_server_tus | 6.5 |
| redhat | enterprise_linux_workstation | 5.0 |
| redhat | enterprise_linux_workstation | 6.0 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/123437.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124108.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124257.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-January/125470.html
- http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00010.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00085.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00086.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00087.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00119.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00120.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00121.html
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00002.html
- http://rhn.redhat.com/errata/RHSA-2013-1812.html
- http://www.mozilla.org/security/announce/2013/mfsa2013-109.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securitytracker.com/id/1029470
- http://www.securitytracker.com/id/1029476
- http://www.ubuntu.com/usn/USN-2052-1
- http://www.ubuntu.com/usn/USN-2053-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=926361
- https://security.gentoo.org/glsa/201504-01
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/123437.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124108.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124257.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-January/125470.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-5618