CVE-2013-0753
Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via crafted web content.
- Affected products
- Centos, Firefox Esr, Firefox, Red Hat, Seamonkey, Suse, Thunderbird, Thunderbird Esr
- Mozilla Firefox
- < 18.0, 10.0.12, 17.0.2
- Mozilla Seamonkey
- < 2.15
- Mozilla Thunderbird
- < 17.0.2
- Mozilla Thunderbird Esr
- < 10.0.12, 17.0.2
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 51.3% (99th percentile)
- Weakness
- CWE-416
- NVD status
- Modified
- Published
- 2013-01-13
CVE-2013-0753 at NVD
8 known exploits for CVE-2013-0753
Proof-of-concept code and exploit modules indexed by Sploitus
Mozilla Firefox XMLSerializer serializeToStream Use-after-free Vulnerability
Mozilla Firefox XMLSerializer serializeToStream Use-after-free Vulnerability
Mozilla Firefox XMLSerializer serializeToStream Use-after-free Vulnerability
Mozilla Firefox XMLSerializer serializeToStream Use-after-free Vulnerability
Firefox XMLSerializer Use After Free Vulnerability
Mozilla Firefox - XMLSerializer Use-After-Free (Metasploit)
Firefox XMLSerializer Use After Free
Firefox XMLSerializer Use After Free