Back

CVE-2013-5613

CRITICAL

Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving synthetic mouse movement, related to the RestyleManager::GetHoverGeneration function.

Published: Dec 11, 2013 Modified: Apr 29, 2026
CWE-416

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (28)

Vendor Product Version
mozilla firefox * < 26.0
mozilla firefox * ≥ 24.0 < 24.2
mozilla seamonkey * < 2.23
mozilla thunderbird * < 24.2
fedoraproject fedora 18
fedoraproject fedora 19
fedoraproject fedora 20
suse suse_linux_enterprise_software_development_kit 11.0
opensuse opensuse 12.2
opensuse opensuse 12.3
opensuse opensuse 13.1
suse suse_linux_enterprise_desktop 11
suse suse_linux_enterprise_server 11
suse suse_linux_enterprise_server 11
redhat enterprise_linux_desktop 5.0
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_eus 6.5
redhat enterprise_linux_server 5.0
redhat enterprise_linux_server 6.0
redhat enterprise_linux_server_aus 6.5

…and 8 more

GitHub Security Advisory GHSA-28w2-h994-g9jp

Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox...

References (44)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 11.06%

Top 6% most likely to be exploited

Threat Score 42.5 / 100

Data Sources

NVD EPSS GitHub