Back

CVE-2013-5618

CRITICAL

Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code by triggering improper garbage collection.

Published: Dec 11, 2013 Modified: Jun 16, 2026
CWE-416

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (28)

Vendor Product Version
mozilla firefox * < 26.0
mozilla firefox * ≥ 24.0 < 24.2
mozilla seamonkey * < 2.23
mozilla thunderbird * < 24.2
fedoraproject fedora 18
fedoraproject fedora 19
fedoraproject fedora 20
suse suse_linux_enterprise_software_development_kit 11.0
opensuse opensuse 12.2
opensuse opensuse 12.3
opensuse opensuse 13.1
suse suse_linux_enterprise_desktop 11
suse suse_linux_enterprise_server 11
suse suse_linux_enterprise_server 11
canonical ubuntu_linux 12.04
canonical ubuntu_linux 12.10
canonical ubuntu_linux 13.04
canonical ubuntu_linux 13.10
redhat enterprise_linux_desktop 5.0
redhat enterprise_linux_desktop 6.0

…and 8 more

GitHub Security Advisory GHSA-24h5-6vcf-hxw3

Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user...

References (42)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 10.41%

Top 5% most likely to be exploited

Threat Score 42.3 / 100

Data Sources

NVD EPSS GitHub