CVE-2013-0754
Use-after-free vulnerability in the ListenerManager implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via vectors involving the triggering of garbage collection after memory allocation for listener objects.
- Affected products
- Centos, Firefox Esr, Firefox, Red Hat, Seamonkey, Suse, Thunderbird, Thunderbird Esr
- Mozilla Firefox
- < 18.0, 10.0.12, 17.0.2
- Mozilla Seamonkey
- < 2.15
- Mozilla Thunderbird
- < 17.0.2
- Mozilla Thunderbird Esr
- < 10.0.12, 17.0.2
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 5.4% (92th percentile)
- Weakness
- CWE-416
- NVD status
- Modified
- Published
- 2013-01-13
CVE-2013-0754 at NVD
No indexed exploits for CVE-2013-0754 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2013-0754 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.