Security Advisory

CVE-2013-1724

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2013-09-18 10:00:00
Last updated 2024-08-06 15:13:32
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

Use-after-free vulnerability in the mozilla::dom::HTMLFormElement::IsDefaultSubmitElement function in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving a destroyed SELECT element.