{"api_version":"1","generated_at":"2026-07-23T11:06:32+00:00","cve":"CVE-2013-0780","urls":{"html":"https://cve.report/CVE-2013-0780","api":"https://cve.report/api/cve/CVE-2013-0780.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-0780","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-0780"},"summary":{"title":"CVE-2013-0780","description":"Use-after-free vulnerability in the nsOverflowContinuationTracker::Finish function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted document that uses Cascading Style Sheets (CSS) -moz-column-* properties.","state":"PUBLISHED","assigner":"mozilla","published_at":"2013-02-19 23:55:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-416","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.ubuntu.com/usn/USN-1729-1","name":"http://www.ubuntu.com/usn/USN-1729-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-1729-1: Firefox vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-0272.html","name":"http://rhn.redhat.com/errata/RHSA-2013-0272.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-1729-2","name":"http://www.ubuntu.com/usn/USN-1729-2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-1729-2: Firefox regression | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-0271.html","name":"http://rhn.redhat.com/errata/RHSA-2013-0271.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-1748-1","name":"http://www.ubuntu.com/usn/USN-1748-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-1748-1: Thunderbird vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2013-02/msg00062.html","name":"http://lists.opensuse.org/opensuse-updates/2013-02/msg00062.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"openSUSE-SU-2013:0324-1: moderate: Mozilla Februarys","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mozilla.org/security/announce/2013/mfsa2013-28.html","name":"http://www.mozilla.org/security/announce/2013/mfsa2013-28.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MFSA 2013-28: Use-after-free, out of bounds read, and buffer overflow issues found using Address Sanitizer","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.html","name":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] openSUSE-SU-2013:0323-1: important: Mozilla: Februar","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2013/dsa-2699","name":"http://www.debian.org/security/2013/dsa-2699","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-2699-1 iceweasel","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=812893","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=812893","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Vendor Advisory"],"title":"812893 – (CVE-2013-0780) Heap-use-after-free in nsOverflowContinuationTracker::Finish, with -moz-columns","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16383","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16383","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-0780","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-0780","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"780","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T14:41:47.259Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"DSA-2699","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2013/dsa-2699"},{"name":"USN-1729-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-1729-1"},{"name":"USN-1729-2","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-1729-2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=812893"},{"name":"USN-1748-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-1748-1"},{"name":"oval:org.mitre.oval:def:16383","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16383"},{"name":"openSUSE-SU-2013:0324","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2013-02/msg00062.html"},{"name":"RHSA-2013:0271","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0271.html"},{"name":"RHSA-2013:0272","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0272.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mozilla.org/security/announce/2013/mfsa2013-28.html"},{"name":"openSUSE-SU-2013:0323","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-02-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"Use-after-free vulnerability in the nsOverflowContinuationTracker::Finish function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted document that uses Cascading Style Sheets (CSS) -moz-column-* properties."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-18T12:57:01.000Z","orgId":"f16b083a-5664-49f3-a51e-8d479e5ed7fe","shortName":"mozilla"},"references":[{"name":"DSA-2699","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2013/dsa-2699"},{"name":"USN-1729-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-1729-1"},{"name":"USN-1729-2","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-1729-2"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=812893"},{"name":"USN-1748-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-1748-1"},{"name":"oval:org.mitre.oval:def:16383","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16383"},{"name":"openSUSE-SU-2013:0324","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2013-02/msg00062.html"},{"name":"RHSA-2013:0271","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0271.html"},{"name":"RHSA-2013:0272","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0272.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mozilla.org/security/announce/2013/mfsa2013-28.html"},{"name":"openSUSE-SU-2013:0323","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@mozilla.org","ID":"CVE-2013-0780","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Use-after-free vulnerability in the nsOverflowContinuationTracker::Finish function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted document that uses Cascading Style Sheets (CSS) -moz-column-* properties."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"DSA-2699","refsource":"DEBIAN","url":"http://www.debian.org/security/2013/dsa-2699"},{"name":"USN-1729-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-1729-1"},{"name":"USN-1729-2","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-1729-2"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=812893","refsource":"CONFIRM","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=812893"},{"name":"USN-1748-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-1748-1"},{"name":"oval:org.mitre.oval:def:16383","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16383"},{"name":"openSUSE-SU-2013:0324","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2013-02/msg00062.html"},{"name":"RHSA-2013:0271","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2013-0271.html"},{"name":"RHSA-2013:0272","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2013-0272.html"},{"name":"http://www.mozilla.org/security/announce/2013/mfsa2013-28.html","refsource":"CONFIRM","url":"http://www.mozilla.org/security/announce/2013/mfsa2013-28.html"},{"name":"openSUSE-SU-2013:0323","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.html"}]}}}},"cveMetadata":{"assignerOrgId":"f16b083a-5664-49f3-a51e-8d479e5ed7fe","assignerShortName":"mozilla","cveId":"CVE-2013-0780","datePublished":"2013-02-19T23:00:00.000Z","dateReserved":"2013-01-02T00:00:00.000Z","dateUpdated":"2024-08-06T14:41:47.259Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-02-19 23:55:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-416","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionEndExcluding":"17.0.3","matchCriteriaId":"20BB7EC3-4F30-448E-9D8C-E00F0D5832DD"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionEndExcluding":"19.0","matchCriteriaId":"C2980165-E0D6-43C0-9AB8-C643B25EF6AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*","versionEndExcluding":"2.16","matchCriteriaId":"60B8F330-4C2F-490C-970E-B22B73B8BE6C"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*","versionEndExcluding":"17.0.3","matchCriteriaId":"E9E0D4E3-BE28-4C02-BF03-483A44E9BDDA"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird_esr:*:*:*:*:*:*:*:*","versionEndExcluding":"17.0.3","matchCriteriaId":"5568CD78-1F01-476D-AA89-D3B3AC3B5172"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*","matchCriteriaId":"DE554781-1EB9-446E-911F-6C11970C47F4"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*","matchCriteriaId":"EBB2C482-D2A4-48B3-ACE7-E1DFDCC409B5"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*","matchCriteriaId":"D806A17E-B8F9-466D-807D-3F1E77603DC8"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_aus:5.9:*:*:*:*:*:*:*","matchCriteriaId":"2E156D3B-17DB-4BE8-9285-C59AF0F25B2B"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*","matchCriteriaId":"133AAFA7-AF42-4D7B-8822-AA2E85611BF5"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*","matchCriteriaId":"EE249E1B-A1FD-4E08-AA71-A0E1F10FFE97"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_eus:5.9:*:*:*:*:*:*:*","matchCriteriaId":"6252E88C-27FF-420D-A64A-C34124CF7E6A"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_eus:6.3:*:*:*:*:*:*:*","matchCriteriaId":"8382A145-CDD9-437E-9DE7-A349956778B3"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*","matchCriteriaId":"54D669D4-6D7E-449D-80C1-28FA44F06FFE"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*","matchCriteriaId":"9BBCD86A-E6C7-4444-9D74-F861084090F0"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*","matchCriteriaId":"D0AC5CD5-6E58-433C-9EB3-6DFE5656463E"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*","matchCriteriaId":"E5ED5807-55B7-47C5-97A6-03233F4FBC3A"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*","matchCriteriaId":"16F59A04-14CF-49E2-9973-645477EA09DA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*","matchCriteriaId":"01EDA41C-6B2E-49AF-B503-EB3882265C11"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*","matchCriteriaId":"E4174F4F-149E-41A6-BBCC-D01114C05F38"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*","matchCriteriaId":"8D305F7A-D159-4716-AB26-5E38BB5CD991"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*","matchCriteriaId":"E2076871-2E80-4605-A470-A41C1A8EC7EE"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"780","Ordinal":"1","Title":"CVE-2013-0780","CVE":"CVE-2013-0780","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"780","Ordinal":"1","NoteData":"Use-after-free vulnerability in the nsOverflowContinuationTracker::Finish function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted document that uses Cascading Style Sheets (CSS) -moz-column-* properties.","Type":"Description","Title":"CVE-2013-0780"},{"CveYear":"2013","CveId":"780","Ordinal":"2","NoteData":"2013-02-19","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"780","Ordinal":"3","NoteData":"2017-09-18","Type":"Other","Title":"Modified"}]}}}