CVE-2013-5615: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 4.2% chance of exploitation in the next 30 days.

The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does not properly enforce certain typeset restrictions on the generation of GetElementIC typed array stubs, which has unspecified impact and remote attack vectors.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 12.10 only; version 13.04 only; version 13.10 only
  • Fedoraproject Fedora: version 18 only; version 19 only; version 20 only
  • Mozilla Firefox: before 26.0 (fixed in 26.0); from 24.0, before 24.2 (fixed in 24.2)
  • Mozilla Seamonkey: before 2.23 (fixed in 2.23)
  • Mozilla Thunderbird: before 24.2 (fixed in 24.2)
  • Opensuse Opensuse: version 12.2 only; version 12.3 only; version 13.1 only
  • Suse Suse Linux Enterprise Desktop: version 11 only
  • Suse Suse Linux Enterprise Server: version 11 only
  • Suse Suse Linux Enterprise Software Development Kit: version 11.0 only

Published 2013-12-11. Last modified 2026-06-16.