CVE-2013-1708: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 3.2% chance of exploitation in the next 30 days.

Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (application crash) via a crafted WAV file that is not properly handled by the nsCString::CharAt function.

Affected products

  • Mozilla Firefox: up to and including 22.0; version 19.0 only; version 19.0.1 only; version 19.0.2 only; version 20.0 only; version 20.0.1 only; …
  • Mozilla Seamonkey: up to and including 2.20; version 2.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; …

Published 2013-08-07. Last modified 2026-06-16.