CVE-2013-1685: Use After Free
Use-after-free vulnerability in the nsIDocument::GetRootElement function in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1685?
CVE-2013-1685 has a high severity rating as it allows remote attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2013-1685?
To fix CVE-2013-1685, update Mozilla Firefox or Thunderbird to versions that are above 22.0 or 17.0.7 respectively.
Which versions are affected by CVE-2013-1685?
CVE-2013-1685 affects multiple versions of Mozilla Firefox prior to 22.0, as well as Thunderbird and their ESR versions before 17.0.7.
What type of vulnerability is CVE-2013-1685?
CVE-2013-1685 is a use-after-free vulnerability in nsIDocument::GetRootElement function.
Can CVE-2013-1685 lead to data leakage?
Yes, CVE-2013-1685 can potentially lead to data leakage as it allows the execution of arbitrary code by attackers.