CVE-2013-1674: Use After Free
Use-after-free vulnerability in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code via vectors involving an onresize event during the playing of a video.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1674?
CVE-2013-1674 has a high severity due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2013-1674?
To fix CVE-2013-1674, update Mozilla Firefox to version 21.0 or later, or update affected Thunderbird versions to 17.0.6 or later.
Which software versions are affected by CVE-2013-1674?
CVE-2013-1674 affects Mozilla Firefox versions before 21.0, Firefox ESR versions before 17.0.6, and Thunderbird versions before 17.0.6.
What can an attacker do exploiting CVE-2013-1674?
An attacker exploiting CVE-2013-1674 can potentially execute arbitrary code on a victim's system.
Is there a workaround for CVE-2013-1674 until I can update?
Currently, there are no recommended workarounds for CVE-2013-1674; updating to the latest versions is the best approach.