CVE-2013-1722

critical
Published 2013-09-18 · Modified 2026-04-29
CVSS v3
VIR risk
9.3

Description

Use-after-free vulnerability in the nsAnimationManager::BuildAnimations function in the Animation Manager in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving stylesheet cloning.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
mozilla mozillathunderbird{"endIncluding":"17.0.9"}
mozilla mozillathunderbird17.0
mozilla mozillathunderbird17.0.1
mozilla mozillathunderbird17.0.2
mozilla mozillathunderbird17.0.3
mozilla mozillathunderbird17.0.4
mozilla mozillathunderbird17.0.5
mozilla mozillathunderbird17.0.6
mozilla mozillathunderbird17.0.7
mozilla mozillathunderbird17.0.8
mozilla mozillafirefox{"endIncluding":"23.0.1"}
mozilla mozillafirefox19.0
mozilla mozillafirefox19.0.1
mozilla mozillafirefox19.0.2
mozilla mozillafirefox20.0
mozilla mozillafirefox20.0.1
mozilla mozillafirefox21.0
mozilla mozillafirefox22.0
mozilla mozillafirefox23.0
mozilla mozillathunderbird_esr17.0
mozilla mozillathunderbird_esr17.0.1
mozilla mozillathunderbird_esr17.0.2
mozilla mozillathunderbird_esr17.0.3
mozilla mozillathunderbird_esr17.0.4
mozilla mozillathunderbird_esr17.0.5
mozilla mozillathunderbird_esr17.0.6
mozilla mozillathunderbird_esr17.0.7
mozilla mozillathunderbird_esr17.0.8
mozilla mozillafirefox17.0
mozilla mozillafirefox17.0.1
mozilla mozillafirefox17.0.2
mozilla mozillafirefox17.0.3
mozilla mozillafirefox17.0.4
mozilla mozillafirefox17.0.5
mozilla mozillafirefox17.0.6
mozilla mozillafirefox17.0.7
mozilla mozillafirefox17.0.8
mozilla mozillaseamonkey{"endIncluding":"2.20"}
mozilla mozillaseamonkey2.0
mozilla mozillaseamonkey2.0.1
mozilla mozillaseamonkey2.0.2
mozilla mozillaseamonkey2.0.3
mozilla mozillaseamonkey2.0.4
mozilla mozillaseamonkey2.0.5
mozilla mozillaseamonkey2.0.6
mozilla mozillaseamonkey2.0.7
mozilla mozillaseamonkey2.0.8
mozilla mozillaseamonkey2.0.9
mozilla mozillaseamonkey2.0.10
mozilla mozillaseamonkey2.0.11
mozilla mozillaseamonkey2.0.12
mozilla mozillaseamonkey2.0.13
mozilla mozillaseamonkey2.0.14
mozilla mozillaseamonkey2.1
mozilla mozillaseamonkey2.10
mozilla mozillaseamonkey2.10.1
mozilla mozillaseamonkey2.11
mozilla mozillaseamonkey2.12
mozilla mozillaseamonkey2.12.1
mozilla mozillaseamonkey2.13
mozilla mozillaseamonkey2.13.1
mozilla mozillaseamonkey2.13.2
mozilla mozillaseamonkey2.14
mozilla mozillaseamonkey2.15
mozilla mozillaseamonkey2.15.1
mozilla mozillaseamonkey2.15.2
mozilla mozillaseamonkey2.16
mozilla mozillaseamonkey2.16.1
mozilla mozillaseamonkey2.16.2
mozilla mozillaseamonkey2.17
mozilla mozillaseamonkey2.17.1
mozilla mozillaseamonkey2.18
mozilla mozillaseamonkey2.19
mozilla mozillaseamonkey2.20

References

CWEs

CWE-399

💬 Discuss CVE-2013-1722 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.