CVE-2013-1705: Mozilla Firefox

High severity, CVSS 10.0. EPSS: 3.9% chance of exploitation in the next 30 days.

Heap-based buffer underflow in the cryptojs_interpret_key_gen_type function in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Certificate Request Message Format (CRMF) request.

Affected products

  • Mozilla Firefox: up to and including 22.0; version 19.0 only; version 19.0.1 only; version 19.0.2 only; version 20.0 only; version 20.0.1 only; …
  • Mozilla Seamonkey: up to and including 2.20; version 2.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; …

Published 2013-08-07. Last modified 2026-06-16.