CVE-2013-0789

critical
Published 2013-04-03 · Modified 2026-04-29
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0 and SeaMonkey before 2.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsContentUtils::HoldJSObjects function and the nsAutoPtr class, and other vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@mozilla.org — http://www.mozilla.org/security/announce/2013/mfsa2013-30.html

Application impact

VendorProductVersionsFixed
mozillafirefox{"endIncluding":"19.0.2"}
mozillafirefox19.0
mozillafirefox19.0.1
mozillaseamonkey{"endIncluding":"2.17"}
mozillaseamonkey2.0
mozillaseamonkey2.0.1
mozillaseamonkey2.0.2
mozillaseamonkey2.0.3
mozillaseamonkey2.0.4
mozillaseamonkey2.0.5
mozillaseamonkey2.0.6
mozillaseamonkey2.0.7
mozillaseamonkey2.0.8
mozillaseamonkey2.0.9
mozillaseamonkey2.0.10
mozillaseamonkey2.0.11
mozillaseamonkey2.0.12
mozillaseamonkey2.0.13
mozillaseamonkey2.0.14
mozillaseamonkey2.1
mozillaseamonkey2.2
mozillaseamonkey2.3
mozillaseamonkey2.3.1
mozillaseamonkey2.3.2
mozillaseamonkey2.3.3
mozillaseamonkey2.4
mozillaseamonkey2.4.1
mozillaseamonkey2.5
mozillaseamonkey2.6
mozillaseamonkey2.6.1
mozillaseamonkey2.7
mozillaseamonkey2.7.1
mozillaseamonkey2.7.2
mozillaseamonkey2.8
mozillaseamonkey2.9
mozillaseamonkey2.9.1
mozillaseamonkey2.10
mozillaseamonkey2.10.1
mozillaseamonkey2.11
mozillaseamonkey2.12
mozillaseamonkey2.12.1
mozillaseamonkey2.13
mozillaseamonkey2.13.1
mozillaseamonkey2.13.2
mozillaseamonkey2.14
mozillaseamonkey2.15
mozillaseamonkey2.15.1
mozillaseamonkey2.15.2
mozillaseamonkey2.16
mozillaseamonkey2.16.1
mozillaseamonkey2.16.2
mozillaseamonkey2.17

References

Verify integrity in audit chain (admin only). AS-IS.