CVE-2013-1735

high

Description

Use-after-free vulnerability in the mozilla::layout::ScrollbarActivity function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code via vectors related to image-document scrolling.

References

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18443

https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-1762

https://bugzilla.mozilla.org/show_bug.cgi?id=898871

http://www.ubuntu.com/usn/USN-1952-1

http://www.ubuntu.com/usn/USN-1951-1

http://www.securityfocus.com/bid/62479

http://www.mozilla.org/security/announce/2013/mfsa2013-90.html

http://www.debian.org/security/2013/dsa-2762

http://rhn.redhat.com/errata/RHSA-2013-1269.html

http://rhn.redhat.com/errata/RHSA-2013-1268.html

http://lists.opensuse.org/opensuse-updates/2013-09/msg00061.html

http://lists.opensuse.org/opensuse-updates/2013-09/msg00060.html

http://lists.opensuse.org/opensuse-updates/2013-09/msg00059.html

http://lists.opensuse.org/opensuse-updates/2013-09/msg00057.html

http://lists.opensuse.org/opensuse-updates/2013-09/msg00055.html

http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00005.html

http://lists.fedoraproject.org/pipermail/package-announce/2013-September/117526.html

http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116610.html

http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115907.html

Details

Source: Mitre, NVD

Published: 2013-09-18

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.03954