peter bassill · operator
$ cve CVE-2013-0753 JSON

CVE-2013-0753 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 51.3% (pctl 99)

Patch early

A public exploit exists.

Description

Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via crafted web content.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS51.32% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-416
On CISA KEVno
Public exploityes
Published2013-01-13
Last modified2026-06-16

Affected (14)

VendorProduct
canonicalubuntu linux
mozillafirefox
mozillaseamonkey
mozillathunderbird
mozillathunderbird esr
opensuseopensuse
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux workstation
suselinux enterprise desktop
suselinux enterprise server
suselinux enterprise software development kit

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD