Synced 30 Sept 2026 20:54 UTC Account
← All products

CVE-2013-0777

HIGH severity · CVSS 9.3 · Use-after-free
9.3CVSS HIGH

Summary

Use-after-free vulnerability in the nsDisplayBoxShadowOuter::Paint function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

Impact & exploitability

Attack vectorNetwork
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)5%

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products we track (1)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.

Official patch: https://bugzilla.mozilla.org/show_bug.cgi?id=798691 ↗