Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-5607


Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.


Published

2013-11-20T14:12:50.697

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-189

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mozilla netscape_portable_runtime ≤ 4.10.1 Yes
Application mozilla netscape_portable_runtime 4.1.1 Yes
Application mozilla netscape_portable_runtime 4.1.2 Yes
Application mozilla netscape_portable_runtime 4.2 Yes
Application mozilla netscape_portable_runtime 4.2.2 Yes
Application mozilla netscape_portable_runtime 4.3 Yes
Application mozilla netscape_portable_runtime 4.4.1 Yes
Application mozilla netscape_portable_runtime 4.5.1 Yes
Application mozilla netscape_portable_runtime 4.6 Yes
Application mozilla netscape_portable_runtime 4.6.1 Yes
Application mozilla netscape_portable_runtime 4.6.2 Yes
Application mozilla netscape_portable_runtime 4.6.3 Yes
Application mozilla netscape_portable_runtime 4.6.4 Yes
Application mozilla netscape_portable_runtime 4.6.5 Yes
Application mozilla netscape_portable_runtime 4.6.6 Yes
Application mozilla netscape_portable_runtime 4.6.7 Yes
Application mozilla netscape_portable_runtime 4.6.8 Yes
Application mozilla netscape_portable_runtime 4.7 Yes
Application mozilla netscape_portable_runtime 4.7.1 Yes
Application mozilla netscape_portable_runtime 4.7.2 Yes
Application mozilla netscape_portable_runtime 4.7.3 Yes
Application mozilla netscape_portable_runtime 4.7.4 Yes
Application mozilla netscape_portable_runtime 4.7.5 Yes
Application mozilla netscape_portable_runtime 4.7.6 Yes
Application mozilla netscape_portable_runtime 4.8 Yes
Application mozilla netscape_portable_runtime 4.8.2 Yes
Application mozilla netscape_portable_runtime 4.8.3 Yes
Application mozilla netscape_portable_runtime 4.8.4 Yes
Application mozilla netscape_portable_runtime 4.8.5 Yes
Application mozilla netscape_portable_runtime 4.8.6 Yes
Application mozilla netscape_portable_runtime 4.8.7 Yes
Application mozilla netscape_portable_runtime 4.8.8 Yes
Application mozilla netscape_portable_runtime 4.8.9 Yes
Application mozilla netscape_portable_runtime 4.9 Yes
Application mozilla netscape_portable_runtime 4.9.1 Yes
Application mozilla netscape_portable_runtime 4.9.2 Yes
Application mozilla netscape_portable_runtime 4.9.3 Yes
Application mozilla netscape_portable_runtime 4.9.4 Yes
Application mozilla netscape_portable_runtime 4.9.5 Yes
Application mozilla netscape_portable_runtime 4.9.6 Yes
Application mozilla netscape_portable_runtime 4.10 Yes
Application mozilla seamonkey ≤ 2.22 Yes
Application mozilla seamonkey 2.0 Yes
Application mozilla seamonkey 2.0 Yes
Application mozilla seamonkey 2.0 Yes
Application mozilla seamonkey 2.0 Yes
Application mozilla seamonkey 2.0 Yes
Application mozilla seamonkey 2.0 Yes
Application mozilla seamonkey 2.0 Yes
Application mozilla seamonkey 2.0 Yes
Application mozilla seamonkey 2.0.1 Yes
Application mozilla seamonkey 2.0.2 Yes
Application mozilla seamonkey 2.0.3 Yes
Application mozilla seamonkey 2.0.4 Yes
Application mozilla seamonkey 2.0.5 Yes
Application mozilla seamonkey 2.0.6 Yes
Application mozilla seamonkey 2.0.7 Yes
Application mozilla seamonkey 2.0.8 Yes
Application mozilla seamonkey 2.0.9 Yes
Application mozilla seamonkey 2.0.10 Yes
Application mozilla seamonkey 2.0.11 Yes
Application mozilla seamonkey 2.0.12 Yes
Application mozilla seamonkey 2.0.13 Yes
Application mozilla seamonkey 2.0.14 Yes
Application mozilla seamonkey 2.1 Yes
Application mozilla seamonkey 2.1 Yes
Application mozilla seamonkey 2.1 Yes
Application mozilla seamonkey 2.1 Yes
Application mozilla seamonkey 2.1 Yes
Application mozilla seamonkey 2.1 Yes
Application mozilla seamonkey 2.1 Yes
Application mozilla seamonkey 2.1 Yes
Application mozilla seamonkey 2.1 Yes
Application mozilla seamonkey 2.10 Yes
Application mozilla seamonkey 2.10 Yes
Application mozilla seamonkey 2.10 Yes
Application mozilla seamonkey 2.10 Yes
Application mozilla seamonkey 2.10.1 Yes
Application mozilla seamonkey 2.11 Yes
Application mozilla seamonkey 2.11 Yes
Application mozilla seamonkey 2.11 Yes
Application mozilla seamonkey 2.11 Yes
Application mozilla seamonkey 2.11 Yes
Application mozilla seamonkey 2.11 Yes
Application mozilla seamonkey 2.11 Yes
Application mozilla seamonkey 2.12 Yes
Application mozilla seamonkey 2.12 Yes
Application mozilla seamonkey 2.12 Yes
Application mozilla seamonkey 2.12 Yes
Application mozilla seamonkey 2.12 Yes
Application mozilla seamonkey 2.12 Yes
Application mozilla seamonkey 2.12 Yes
Application mozilla seamonkey 2.12.1 Yes
Application mozilla seamonkey 2.13 Yes
Application mozilla seamonkey 2.13 Yes
Application mozilla seamonkey 2.13 Yes
Application mozilla seamonkey 2.13 Yes
Application mozilla seamonkey 2.13 Yes
Application mozilla seamonkey 2.13 Yes
Application mozilla seamonkey 2.13 Yes
Application mozilla seamonkey 2.13.1 Yes
Application mozilla seamonkey 2.13.2 Yes
Application mozilla seamonkey 2.14 Yes
Application mozilla seamonkey 2.14 Yes
Application mozilla seamonkey 2.14 Yes
Application mozilla seamonkey 2.14 Yes
Application mozilla seamonkey 2.14 Yes
Application mozilla seamonkey 2.14 Yes
Application mozilla seamonkey 2.15 Yes
Application mozilla seamonkey 2.15 Yes
Application mozilla seamonkey 2.15 Yes
Application mozilla seamonkey 2.15 Yes
Application mozilla seamonkey 2.15 Yes
Application mozilla seamonkey 2.15 Yes
Application mozilla seamonkey 2.15 Yes
Application mozilla seamonkey 2.15.1 Yes
Application mozilla seamonkey 2.15.2 Yes
Application mozilla seamonkey 2.16 Yes
Application mozilla seamonkey 2.16 Yes
Application mozilla seamonkey 2.16 Yes
Application mozilla seamonkey 2.16 Yes
Application mozilla seamonkey 2.16 Yes
Application mozilla seamonkey 2.16 Yes
Application mozilla seamonkey 2.16.1 Yes
Application mozilla seamonkey 2.16.2 Yes
Application mozilla seamonkey 2.17 Yes
Application mozilla seamonkey 2.17 Yes
Application mozilla seamonkey 2.17 Yes
Application mozilla seamonkey 2.17 Yes
Application mozilla seamonkey 2.17 Yes
Application mozilla seamonkey 2.17.1 Yes
Application mozilla seamonkey 2.18 Yes
Application mozilla seamonkey 2.18 Yes
Application mozilla seamonkey 2.18 Yes
Application mozilla seamonkey 2.18 Yes
Application mozilla seamonkey 2.19 Yes
Application mozilla seamonkey 2.19 Yes
Application mozilla seamonkey 2.19 Yes
Application mozilla seamonkey 2.20 Yes
Application mozilla seamonkey 2.20 Yes
Application mozilla seamonkey 2.20 Yes
Application mozilla seamonkey 2.20 Yes
Application mozilla seamonkey 2.21 Yes
Application mozilla seamonkey 2.21 Yes
Application mozilla seamonkey 2.21 Yes
Application mozilla seamonkey 2.22 Yes
Application mozilla seamonkey 2.22 Yes
Application mozilla firefox 17.0 Yes
Application mozilla firefox 17.0.1 Yes
Application mozilla firefox 17.0.2 Yes
Application mozilla firefox 17.0.3 Yes
Application mozilla firefox 17.0.4 Yes
Application mozilla firefox 17.0.5 Yes
Application mozilla firefox 17.0.6 Yes
Application mozilla firefox 17.0.7 Yes
Application mozilla firefox 17.0.8 Yes
Application mozilla firefox 17.0.9 Yes
Application mozilla firefox 17.0.10 Yes
Application mozilla firefox 24.0 Yes
Application mozilla firefox_esr 24.0.1 Yes
Application mozilla firefox_esr 24.0.2 Yes
Application mozilla firefox ≤ 25.0 Yes
Application mozilla firefox 19.0 Yes
Application mozilla firefox 19.0.1 Yes
Application mozilla firefox 19.0.2 Yes
Application mozilla firefox 20.0 Yes
Application mozilla firefox 20.0.1 Yes
Application mozilla firefox 21.0 Yes
Application mozilla firefox 22.0 Yes
Application mozilla firefox 23.0 Yes
Application mozilla firefox 23.0.1 Yes
Application mozilla firefox 24.0 Yes

References