CVE-2013-5610

CRITICAL

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and applic...

Affects 9 products across 6 vendors.

BCS7.51
CVSS 2.010.0
EPSS6.5%
Percentile93th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-787: Out-of-Bounds Write

Software writes data past buffer boundaries, corrupting memory and potentially enabling code execution.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2013. A critical vulnerability affects Canonical systems (CVE-2013-5610). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2013-GLOBAL-296802-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2013-5610?
This vulnerability was disclosed in 2013. A critical vulnerability affects Canonical systems (CVE-2013-5610). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2013-5610?
CVE-2013-5610 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 6.5%.
Is CVE-2013-5610 actively exploited?
No confirmed active exploitation of CVE-2013-5610 as of 2026-05-30.
How do I remediate CVE-2013-5610?
Priority: MEDIUM. Advisory: http://www.mozilla.org/security/announce/2013/mfsa2013-104.html PSIRT: [email protected]
What systems are affected by CVE-2013-5610?
CVE-2013-5610 affects: Canonical, Fedoraproject, Mozilla, Mozilla, Opensuse, Oracle, Suse, Suse.
Vulnerability Details
CVE IDCVE-2013-5610
BSIDBS-2013-GLOBAL-296802-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2013-12-11
Last Modified2026-04-29
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Canonical Ubuntu Linux
Fedoraproject Fedora
Mozilla Firefox
Mozilla Seamonkey
Opensuse Opensuse
Oracle Solaris
Suse Linux Enterprise Software Development Kit
Suse Linux Enterprise Server
Suse Linux Enterprise Desktop
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 4616 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash82e68cffaacf5cd8ef8ad4a3c7d43999a1fde98e80383c42ba9868407242cdd584abe5ce60d79fd89618fefd43de4836a079d82804589f15a90982eff4b66158
Related CVEs affecting Canonical
CVE-2012-0444 10.0 Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 ... CVE-2004-1018 10.0 Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypa... CVE-2004-1063 10.0 PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multit... CVE-2007-2442 10.0 The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb... CVE-2012-4212 10.0 Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozill...
View all Canonical CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →