CVE-2013-1724
Use-after-free vulnerability in the mozilla::dom::HTMLFormElement::IsDefaultSubmitElement function in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving a destroyed SELECT element.
- Affected products
- Alt Linux, Firefox, Seamonkey, Suse, Thunderbird
- Mozilla Seamonkey
- ≤ 2.20, 2.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.1, 2.10, 2.10.1, 2.11, 2.12, 2.12.1, 2.13, 2.13.1, 2.13.2, 2.14, 2.15, 2.15.1, 2.15.2, 2.16, 2.16.1, 2.16.2, 2.17, 2.17.1, 2.18, 2.19
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 5.7% (92th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2013-09-18
CVE-2013-1724 at NVD
1 known exploit for CVE-2013-1724
Proof-of-concept code and exploit modules indexed by Sploitus