← All CVEs

CVE-2013-1675

medium · 6.5Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-03Remediation due 2022-03-24

Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

6.5
CVSS
6.7%
EPSS (exploit prob.)
94th
EPSS percentile
2013-05-16
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Weaknesses

CWE-665

Affected products

VendorProductAffected versions
mozillafirefox< 21.0
mozillafirefox>= 17.0, < 17.0.6
mozillathunderbird< 17.0.6
mozillathunderbird_esr>= 17.0, < 17.0.6
canonicalubuntu_linux12.04
canonicalubuntu_linux12.10
canonicalubuntu_linux13.04
debiandebian_linux7.0
redhatgluster_storage_server_for_on-premise2.1
redhatenterprise_linux_desktop5.0
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_eus5.9
redhatenterprise_linux_eus6.4
redhatenterprise_linux_for_ibm_z_systems5.0_s390x
redhatenterprise_linux_for_ibm_z_systems6.0_s390x
redhatenterprise_linux_for_ibm_z_systems_eus5.9_s390x
redhatenterprise_linux_for_ibm_z_systems_eus6.4_s390x
redhatenterprise_linux_for_power_big_endian5.0_ppc
redhatenterprise_linux_for_power_big_endian6.0_ppc64
redhatenterprise_linux_for_power_big_endian_eus5.9_ppc
redhatenterprise_linux_for_power_big_endian_eus6.4_ppc64
redhatenterprise_linux_for_scientific_computing6.0
redhatenterprise_linux_server5.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_server_aus5.9
redhatenterprise_linux_server_aus6.4
redhatenterprise_linux_server_eus_from_rhui5.9
redhatenterprise_linux_server_eus_from_rhui6.4
redhatenterprise_linux_workstation5.0
redhatenterprise_linux_workstation6.0
opensuseopensuse12.2
opensuseopensuse12.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-1675