CVE-2013-1732
Summary
| CVE | CVE-2013-1732 |
|---|---|
| State | PUBLISHED |
| Assigner | mozilla |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-09-18 10:08:24 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Buffer overflow in the nsFloatManager::GetFlowArea function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code via crafted use of lists and floats within a multi-column layout. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 17.0 | All | All | All |
| Application | Mozilla | Firefox | 17.0.1 | All | All | All |
| Application | Mozilla | Firefox | 17.0.2 | All | All | All |
| Application | Mozilla | Firefox | 17.0.3 | All | All | All |
| Application | Mozilla | Firefox | 17.0.4 | All | All | All |
| Application | Mozilla | Firefox | 17.0.5 | All | All | All |
| Application | Mozilla | Firefox | 17.0.6 | All | All | All |
| Application | Mozilla | Firefox | 17.0.7 | All | All | All |
| Application | Mozilla | Firefox | 17.0.8 | All | All | All |
| Application | Mozilla | Firefox | 19.0 | All | All | All |
| Application | Mozilla | Firefox | 19.0.1 | All | All | All |
| Application | Mozilla | Firefox | 19.0.2 | All | All | All |
| Application | Mozilla | Firefox | 20.0 | All | All | All |
| Application | Mozilla | Firefox | 20.0.1 | All | All | All |
| Application | Mozilla | Firefox | 21.0 | All | All | All |
| Application | Mozilla | Firefox | 22.0 | All | All | All |
| Application | Mozilla | Firefox | 23.0 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Seamonkey | 2.0 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_2 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_3 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | beta_1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | beta_2 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | rc1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | rc2 | All | All |
| Application | Mozilla | Seamonkey | 2.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.10 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.11 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.12 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.13 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.14 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.2 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.3 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.4 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.5 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.6 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.7 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.8 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.9 | All | All | All |
| Application | Mozilla | Seamonkey | 2.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.1 | alpha1 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | alpha2 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | alpha3 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | rc1 | All | All |
| Application | Mozilla | Seamonkey | 2.1 | rc2 | All | All |
| Application | Mozilla | Seamonkey | 2.10 | All | All | All |
| Application | Mozilla | Seamonkey | 2.10 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.10 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.10 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.10.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.11 | All | All | All |
| Application | Mozilla | Seamonkey | 2.11 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.11 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.11 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.11 | beta4 | All | All |
| Application | Mozilla | Seamonkey | 2.11 | beta5 | All | All |
| Application | Mozilla | Seamonkey | 2.11 | beta6 | All | All |
| Application | Mozilla | Seamonkey | 2.12 | All | All | All |
| Application | Mozilla | Seamonkey | 2.12 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.12 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.12 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.12 | beta4 | All | All |
| Application | Mozilla | Seamonkey | 2.12 | beta5 | All | All |
| Application | Mozilla | Seamonkey | 2.12 | beta6 | All | All |
| Application | Mozilla | Seamonkey | 2.12.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.13 | All | All | All |
| Application | Mozilla | Seamonkey | 2.13 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.13 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.13 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.13 | beta4 | All | All |
| Application | Mozilla | Seamonkey | 2.13 | beta5 | All | All |
| Application | Mozilla | Seamonkey | 2.13 | beta6 | All | All |
| Application | Mozilla | Seamonkey | 2.13.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.13.2 | All | All | All |
| Application | Mozilla | Seamonkey | 2.14 | All | All | All |
| Application | Mozilla | Seamonkey | 2.14 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.14 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.14 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.14 | beta4 | All | All |
| Application | Mozilla | Seamonkey | 2.14 | beta5 | All | All |
| Application | Mozilla | Seamonkey | 2.15 | All | All | All |
| Application | Mozilla | Seamonkey | 2.15 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.15 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.15 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.15 | beta4 | All | All |
| Application | Mozilla | Seamonkey | 2.15 | beta5 | All | All |
| Application | Mozilla | Seamonkey | 2.15 | beta6 | All | All |
| Application | Mozilla | Seamonkey | 2.15.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.15.2 | All | All | All |
| Application | Mozilla | Seamonkey | 2.16 | All | All | All |
| Application | Mozilla | Seamonkey | 2.16 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.16 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.16 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.16 | beta4 | All | All |
| Application | Mozilla | Seamonkey | 2.16 | beta5 | All | All |
| Application | Mozilla | Seamonkey | 2.16.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.16.2 | All | All | All |
| Application | Mozilla | Seamonkey | 2.17 | All | All | All |
| Application | Mozilla | Seamonkey | 2.17 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.17 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.17 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.17 | beta4 | All | All |
| Application | Mozilla | Seamonkey | 2.17.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.18 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.18 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.18 | beta3 | All | All |
| Application | Mozilla | Seamonkey | 2.18 | beta4 | All | All |
| Application | Mozilla | Seamonkey | 2.19 | All | All | All |
| Application | Mozilla | Seamonkey | 2.19 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.19 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.20 | beta1 | All | All |
| Application | Mozilla | Seamonkey | 2.20 | beta2 | All | All |
| Application | Mozilla | Seamonkey | 2.20 | beta3 | All | All |
| Application | Mozilla | Seamonkey | All | All | All | All |
| Application | Mozilla | Thunderbird | 17.0 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.1 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.3 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.4 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.5 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.6 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.7 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.8 | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.1 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.2 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.3 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.4 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.5 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.6 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.7 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.8 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 883514 – (CVE-2013-1732) Global buffer overflow (read 4) at nsFloatManager::GetFlowArea() with multicol, list, floats | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| openSUSE-SU-2013:1496-1: moderate: update for xulrunner17 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| openSUSE-SU-2013:1499-1: moderate: Mozilla updates September 2013 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [SECURITY] Fedora 18 Update: firefox-24.0-1.fc18 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Debian -- Security Information -- DSA-2762-1 icedove | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Mozilla Firefox/Thunderbird/SeaMonkey CVE-2013-1732 Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| USN-1951-1: Firefox vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| MFSA 2013-89: Buffer overflow with multi-column, lists, and floats | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| [security-announce] openSUSE-SU-2013:1633-1: important: Mozilla Suite: U | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| openSUSE-SU-2013:1493-1: moderate: update for MozillaFirefox | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [SECURITY] Fedora 19 Update: firefox-24.0-1.fc19 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| openSUSE-SU-2013:1491-1: moderate: update for seamonkey | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| openSUSE-SU-2013:1495-1: moderate: update for MozillaThunderbird | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| USN-1952-1: Thunderbird vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| [SECURITY] Fedora 20 Update: firefox-24.0-1.fc20 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.