Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2013-1720

N/A

The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 does not properly maintain the state of the insertion-mode stack for template elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer over-read) by triggering use of this stack in its empty state.

EPSS 3.99% above median percentile 89.6%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (10)
Vendor Product Versions
mozilla thunderbird
All platforms (wildcard)
≤17.0.9
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
View on NVD ↗ Advisory · www.mozilla.org