CVE-2013-5603: Mozilla Firefox

High severity, CVSS 10.0. EPSS: 5.4% chance of exploitation in the next 30 days.

Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving HTML document templates.

Affected products

  • Mozilla Firefox: version 24.0 only; version 24.0.1 only; version 24.0.2 only; up to and including 24.0; version 19.0 only; version 19.0.1 only; …
  • Mozilla Seamonkey: up to and including 2.22; version 2.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; …
  • Mozilla Thunderbird: up to and including 24.0.1; version 17.0 only; version 17.0.1 only; version 17.0.2 only; version 17.0.3 only; version 17.0.4 only; …
  • Mozilla Thunderbird ESR: version 17.0.9 only

Published 2013-10-30. Last modified 2026-06-16.