CVE-2013-5603
Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving HTML document templates.
- Affected products
- Alt Linux, Firefox Esr, Firefox, Seamonkey, Suse, Thunderbird
- Mozilla Thunderbird
- ≤ 24.0.1, 17.0, 17.0.1, 17.0.2, 17.0.3, 17.0.4, 17.0.5, 17.0.6, 17.0.7, 17.0.8, 24.0
- Mozilla Thunderbird Esr
- = 17.0.9
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 5.4% (92th percentile)
- NVD status
- Modified
- Published
- 2013-10-30
CVE-2013-5603 at NVD
No indexed exploits for CVE-2013-5603 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2013-5603 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.