CVE-2013-1680: Buffer Overflow
Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1680?
CVE-2013-1680 is classified as a critical vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2013-1680?
To fix CVE-2013-1680, upgrade Mozilla Firefox to version 21.0 or later, Firefox ESR to version 17.0.6 or later, or Thunderbird to version 17.0.6 or later.
Which versions of Firefox are affected by CVE-2013-1680?
CVE-2013-1680 affects Mozilla Firefox versions prior to 21.0, specifically 20.0.1 and earlier.
Which versions of Thunderbird are impacted by CVE-2013-1680?
CVE-2013-1680 impacts Thunderbird versions prior to 17.0.6, including 17.0 and earlier.
What type of vulnerability is CVE-2013-1680?
CVE-2013-1680 is a use-after-free vulnerability in the nsFrameList::FirstChild function.