CVE-2013-1675
medium · 6.5Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-03-03Remediation due 2022-03-24
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
6.5
CVSS
6.7%
EPSS (exploit prob.)
94th
EPSS percentile
2013-05-16
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weaknesses
CWE-665
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| mozilla | firefox | < 21.0 |
| mozilla | firefox | >= 17.0, < 17.0.6 |
| mozilla | thunderbird | < 17.0.6 |
| mozilla | thunderbird_esr | >= 17.0, < 17.0.6 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 12.10 |
| canonical | ubuntu_linux | 13.04 |
| debian | debian_linux | 7.0 |
| redhat | gluster_storage_server_for_on-premise | 2.1 |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_eus | 5.9 |
| redhat | enterprise_linux_eus | 6.4 |
| redhat | enterprise_linux_for_ibm_z_systems | 5.0_s390x |
| redhat | enterprise_linux_for_ibm_z_systems | 6.0_s390x |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 5.9_s390x |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 6.4_s390x |
| redhat | enterprise_linux_for_power_big_endian | 5.0_ppc |
| redhat | enterprise_linux_for_power_big_endian | 6.0_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 5.9_ppc |
| redhat | enterprise_linux_for_power_big_endian_eus | 6.4_ppc64 |
| redhat | enterprise_linux_for_scientific_computing | 6.0 |
| redhat | enterprise_linux_server | 5.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server_aus | 5.9 |
| redhat | enterprise_linux_server_aus | 6.4 |
| redhat | enterprise_linux_server_eus_from_rhui | 5.9 |
| redhat | enterprise_linux_server_eus_from_rhui | 6.4 |
| redhat | enterprise_linux_workstation | 5.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| opensuse | opensuse | 12.2 |
| opensuse | opensuse | 12.3 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.html
- http://rhn.redhat.com/errata/RHSA-2013-0820.html
- http://rhn.redhat.com/errata/RHSA-2013-0821.html
- http://www.debian.org/security/2013/dsa-2699
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:165
- http://www.mozilla.org/security/announce/2013/mfsa2013-47.html
- http://www.securityfocus.com/bid/59858
- http://www.ubuntu.com/usn/USN-1822-1
- http://www.ubuntu.com/usn/USN-1823-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=866825
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16976
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.html
- http://rhn.redhat.com/errata/RHSA-2013-0820.html
- http://rhn.redhat.com/errata/RHSA-2013-0821.html
- http://www.debian.org/security/2013/dsa-2699
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:165
- http://www.mozilla.org/security/announce/2013/mfsa2013-47.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-1675