CVE-2013-5597
Summary
| CVE | CVE-2013-5597 |
|---|---|
| State | PUBLISHED |
| Assigner | mozilla |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-10-30 10:55:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Use-after-free vulnerability in the nsDocLoader::doStopDocumentLoad function in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving a state-change event during an update of the offline cache. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Thunderbird | 17.0 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.1 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.3 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.4 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.5 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.6 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.7 | All | All | All |
| Application | Mozilla | Thunderbird | 17.0.8 | All | All | All |
| Application | Mozilla | Thunderbird | 24.0 | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.1 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.2 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.3 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.4 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.5 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.6 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.7 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.8 | All | All | All |
| Application | Mozilla | Thunderbird Esr | 17.0.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Gentoo Security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Debian -- Security Information -- DSA-2797-1 icedove | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Access Denied | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| MFSA 2013-98: Use-after-free when updating offline cache | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| [security-announce] SUSE-SU-2013:1678-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2013:1633-1: important: Mozilla Suite: U | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| [security-announce] openSUSE-SU-2013:1634-1: important: Mozilla updates | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Debian -- Security Information -- DSA-2788-1 iceweasel | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.