CVE-2013-1591: Palemoon Pale Moon

Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.

Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent attack vectors. NOTE: this issue might be resultant from an integer overflow in the fast_composite_scaled_bilinear function in pixman-inlines.h, which triggers an infinite loop.

Affected products

  • Palemoon Pale Moon: before 15.4 (fixed in 15.4)
  • Red Hat Enterprise Linux: version 6.0 only
  • Red Hat Enterprise Virtualization: version 3.0 only

Published 2013-01-31. Last modified 2026-06-16.