V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2013-1675
DEB
Medium KEVConfirmedExploit available

Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not prope…

CVSS
6.5
Medium
EPSS
0.08
p92
Published
2013-01-01
Updated
2022-03-03
Description

Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

Tags · CWE
KEVPre-auth
CWE-456
CWE-665
CAPEC-26
CAPEC-29
Affected products
Debian_linux
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Timeline
2013-01-01
Published
2022-03-03
Added to KEV
2022-03-03
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.079 · p92
Known exploited (KEV)
Yes
Known exploits — Сканер-ВС
CVE-2013-1675
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Enterprise
Affected software
ProductVendorStatus
firefoxExploited
firefoxExploited
iceapeExploited
iceapeExploited
iceapeExploited
icedoveExploited
icedoveExploited
iceweaselExploited
iceweaselExploited
thunderbirdExploited
thunderbirdExploited
xulrunnerExploited
xulrunnerExploited
debian_linux*Exploited
enterprise_linux_desktop*Exploited
enterprise_linux_eus*Exploited
enterprise_linux_for_ibm_z_systems*Exploited
enterprise_linux_for_ibm_z_systems_eus*Exploited
enterprise_linux_for_power_big_endian*Exploited
enterprise_linux_for_power_big_endian_eus*Exploited
Source databases
DEB
CVE
RED