CVE-2013-0801

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

Published: 2013-05-16 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2013-0801 is rated High Risk (75.9/100): CVSS Critical severity, with high exploitation likelihood (EPSS 5.39%, 92th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +3.84% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2013-0801

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 1.56% 5.39% +3.84%
2 2025-03-30 5.58% 1.56% -4.03%
3 2025-03-29 5.58%

Full EPSS history (11 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2013-0801

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
10.0 2.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 10.0 [email protected]

Weakness enumeration for CVE-2013-0801

OS Trackers for CVE-2013-0801

vendor priority summary link
gentoo high CVE-2013-0801: 1 GLSA(s) (201309-23), 6 atom(s) (mail-client/thunderbird, mail-client/thunderbird-bin, www-client/firefox, www-client/firefox-bin, www-client/seamonkey, www-client/seamonkey-bin); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2013-0801
redhat critical https://access.redhat.com/security/cve/CVE-2013-0801
suse critical CVE-2013-0801 severity critical: SUSE including 57 source package names (MozillaFirefox-140.2.0-160000.1.2, MozillaFirefox-31.1.0esr-1.20, …), 73 product×package rows across 28 product lines (SUSE Linux Enterprise Desktop 12, SUSE Linux Enterprise Desktop 12 SP1, … (28 product lines)): Fixed 73. https://www.suse.com/security/cve/CVE-2013-0801/
ubuntu medium CVE-2013-0801 medium priority: Ubuntu including 4 source packages (firefox, seamonkey, thunderbird, xulrunner-1.9.2), 20 status rows across 5 suites (lucid, precise, quantal, raring, upstream): released 8, DNE 6, ignored 4, needs-triage 2. https://ubuntu.com/security/CVE-2013-0801

Affected software / configurations for CVE-2013-0801

Vendor Product Version Raw CPE
mozilla firefox <= 20.0.1 cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozilla firefox 19.0 cpe:2.3:a:mozilla:firefox:19.0:*:*:*:*:*:*:*
mozilla firefox 19.0.1 cpe:2.3:a:mozilla:firefox:19.0.1:*:*:*:*:*:*:*
mozilla firefox 19.0.2 cpe:2.3:a:mozilla:firefox:19.0.2:*:*:*:*:*:*:*
mozilla firefox 20.0 cpe:2.3:a:mozilla:firefox:20.0:*:*:*:*:*:*:*
mozilla firefox 17.0 cpe:2.3:a:mozilla:firefox:17.0:*:*:*:*:*:*:*
mozilla firefox 17.0.1 cpe:2.3:a:mozilla:firefox:17.0.1:*:*:*:*:*:*:*
mozilla firefox 17.0.2 cpe:2.3:a:mozilla:firefox:17.0.2:*:*:*:*:*:*:*
mozilla firefox 17.0.3 cpe:2.3:a:mozilla:firefox:17.0.3:*:*:*:*:*:*:*
mozilla firefox 17.0.4 cpe:2.3:a:mozilla:firefox:17.0.4:*:*:*:*:*:*:*
mozilla firefox 17.0.5 cpe:2.3:a:mozilla:firefox:17.0.5:*:*:*:*:*:*:*
mozilla thunderbird <= 17.0.5 cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
mozilla thunderbird 17.0 cpe:2.3:a:mozilla:thunderbird:17.0:*:*:*:*:*:*:*
mozilla thunderbird 17.0.1 cpe:2.3:a:mozilla:thunderbird:17.0.1:*:*:*:*:*:*:*
mozilla thunderbird 17.0.2 cpe:2.3:a:mozilla:thunderbird:17.0.2:*:*:*:*:*:*:*
mozilla thunderbird 17.0.3 cpe:2.3:a:mozilla:thunderbird:17.0.3:*:*:*:*:*:*:*
mozilla thunderbird 17.0.4 cpe:2.3:a:mozilla:thunderbird:17.0.4:*:*:*:*:*:*:*
mozilla thunderbird_esr 17.0 cpe:2.3:a:mozilla:thunderbird_esr:17.0:*:*:*:*:*:*:*
mozilla thunderbird_esr 17.0.1 cpe:2.3:a:mozilla:thunderbird_esr:17.0.1:*:*:*:*:*:*:*
mozilla thunderbird_esr 17.0.2 cpe:2.3:a:mozilla:thunderbird_esr:17.0.2:*:*:*:*:*:*:*
mozilla thunderbird_esr 17.0.3 cpe:2.3:a:mozilla:thunderbird_esr:17.0.3:*:*:*:*:*:*:*
mozilla thunderbird_esr 17.0.4 cpe:2.3:a:mozilla:thunderbird_esr:17.0.4:*:*:*:*:*:*:*
mozilla thunderbird_esr 17.0.5 cpe:2.3:a:mozilla:thunderbird_esr:17.0.5:*:*:*:*:*:*:*

References for CVE-2013-0801

URL Tags
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.html
http://rhn.redhat.com/errata/RHSA-2013-0820.html
http://rhn.redhat.com/errata/RHSA-2013-0821.html
http://www.debian.org/security/2013/dsa-2699
http://www.mandriva.com/security/advisories?name=MDVSA-2013:165
http://www.mozilla.org/security/announce/2013/mfsa2013-41.html Vendor Advisory
http://www.securityfocus.com/bid/59855
http://www.ubuntu.com/usn/USN-1822-1
http://www.ubuntu.com/usn/USN-1823-1
https://bugzilla.mozilla.org/show_bug.cgi?id=787283
https://bugzilla.mozilla.org/show_bug.cgi?id=808402
https://bugzilla.mozilla.org/show_bug.cgi?id=849597
https://bugzilla.mozilla.org/show_bug.cgi?id=852315
https://bugzilla.mozilla.org/show_bug.cgi?id=864558
https://bugzilla.mozilla.org/show_bug.cgi?id=866544
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17062
cvelogic Threat Intelligence