Back
CVE-2013-5618
CRITICAL
Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code by triggering improper garbage collection.
Published: Dec 11, 2013
Modified: Jun 16, 2026
CWE-416
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (28)
| Vendor | Product | Version |
|---|---|---|
| mozilla | firefox | * < 26.0 |
| mozilla | firefox | * ≥ 24.0 < 24.2 |
| mozilla | seamonkey | * < 2.23 |
| mozilla | thunderbird | * < 24.2 |
| fedoraproject | fedora | 18 |
| fedoraproject | fedora | 19 |
| fedoraproject | fedora | 20 |
| suse | suse_linux_enterprise_software_development_kit | 11.0 |
| opensuse | opensuse | 12.2 |
| opensuse | opensuse | 12.3 |
| opensuse | opensuse | 13.1 |
| suse | suse_linux_enterprise_desktop | 11 |
| suse | suse_linux_enterprise_server | 11 |
| suse | suse_linux_enterprise_server | 11 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 12.10 |
| canonical | ubuntu_linux | 13.04 |
| canonical | ubuntu_linux | 13.10 |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_desktop | 6.0 |
…and 8 more
GitHub Security Advisory GHSA-24h5-6vcf-hxw3
Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user...
References (42)
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/123437.html Mailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124108.html Mailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124257.html Mailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-January/125470.html Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00010.html Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00085.html Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00086.html Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00087.html Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00119.html Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00120.html Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00121.html Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00002.html Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1812.html Third Party Advisory
- http://www.mozilla.org/security/announce/2013/mfsa2013-109.html Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
10.41%
Top 5% most likely to be exploited
Threat Score
42.3 / 100
Data Sources
NVD
EPSS
GitHub