The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 does not properly maintain the state of the insertion-mode stack for template elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer over-read) by triggering use of this stack in its empty state.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade thunderbirdUpgrade linux-seamonkeyUpgrade firefoxUpgrade linux-thunderbirdUpgrade linux-firefoxUpgrade seamonkey | Dec 10, 2025 | Aug 18, 2013 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird.Upgrade www-client/firefox.Upgrade www-client/seamonkey.Upgrade www-client/seamonkey-bin.Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird-bin. | Oct 30, 2017 | Sep 18, 2013 |
| Mfsa2013 77 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 24.0 | Sep 25, 2013 | Sep 18, 2013 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.21.0 | Dec 8, 2014 | Sep 18, 2013 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 24.0 | Sep 25, 2013 | Sep 18, 2013 |
| Suse | — | Upgrade mozillafirefox-branding-upstreamUpgrade mozillafirefox-buildsymbolsUpgrade MozillaFirefox-translations-commonUpgrade seamonkey-dom-inspectorUpgrade MozillaThunderbird-buildsymbolsUpgrade enigmailUpgrade seamonkey-translations-commonUpgrade MozillaFirefoxUpgrade seamonkeyUpgrade seamonkey-translations-otherUpgrade MozillaFirefox-develUpgrade MozillaThunderbird-translations-commonUpgrade MozillaThunderbirdUpgrade MozillaFirefox-translations-otherUpgrade seamonkey-ircUpgrade seamonkey-venkmanUpgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbird-devel | Dec 12, 2013 | Sep 18, 2013 |
| Ubuntu | — | Upgrade thunderbirdUpgrade firefox | Nov 8, 2024 | Sep 18, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub