CVE-2013-0791 Details
Description
The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted certificate.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mozilla firefox | <= 20.0 >= 17.0, < 17.0.5 |
CPE
Remediation
| |
| mozilla network security services | < 3.15 |
CPE
Remediation
| |
| mozilla seamonkey | < 2.17 |
CPE
Remediation
| |
| mozilla thunderbird | < 17.0.5 |
CPE
Remediation
| |
| mozilla thunderbird esr | >= 17.0, < 17.0.5 |
CPE
Remediation
| |
| canonical ubuntu linux | 10.04 11.10 12.04 12.10 |
CPE
Remediation
| |
| oracle vm server | 3.2 |
CPE
Remediation
| |
| redhat enterprise linux desktop | 5.0 6.0 |
CPE
Remediation
| |
| redhat enterprise linux eus | 5.9 |
CPE
Remediation
| |
| redhat enterprise linux server | 5.0 6.0 |
CPE
Remediation
| |
| redhat enterprise linux server aus | 5.9 |
CPE
Remediation
| |
| redhat enterprise linux workstation | 5.0 6.0 |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Apr 29, 2026 | Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Oct 21, 2024 | CPE Deprecation Remap | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 21, 2022 | Modified Analysis | [email protected] |
| Sep 19, 2017 | CVE Modified | [email protected] |
| Dec 31, 2016 | CVE Modified | [email protected] |
| Nov 28, 2016 | CVE Modified | [email protected] |
| Sep 9, 2016 | CVE Modified | [email protected] |
| Apr 3, 2013 | Initial Analysis | [email protected] |