The cycle collection (CC) implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly determine the thread for release of an image object, which allows remote attackers to execute arbitrary code or cause a denial of service (race condition and application crash) via a large HTML document containing IMG elements, as demonstrated by the Never-Ending Reddit on reddit.com.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
21 Nov 2024, 01:57
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00005.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00006.html - | |
References | () http://www.mozilla.org/security/announce/2013/mfsa2013-97.html - Vendor Advisory | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=910881 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19066 - | |
References | () https://security.gentoo.org/glsa/201504-01 - |
21 Oct 2024, 13:55
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:mozilla:firefox:24.0:*:*:*:*:*:*:* |
Information
Published : 2013-10-30 10:55
Updated : 2024-11-21 01:57
NVD link : CVE-2013-5596
Mitre link : CVE-2013-5596
CVE.ORG link : CVE-2013-5596
JSON object : View
Products Affected
mozilla
- firefox
- thunderbird
- seamonkey
- thunderbird_esr
- firefox_esr
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer