TROYANOSYVIRUS
Back to CVEs

CVE-2013-1675

MEDIUMCISA KEV
6.5

Description

Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

CVE Details

CVSS v3.1 Score6.5
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
Published5/16/2013
Last Modified4/22/2026
Sourcekev
Honeypot Sightings0

CISA KEV

VendorMozilla
ProductFirefox
Vulnerability NameMozilla Firefox Information Disclosure Vulnerability
KEV Date Added2022-03-03
Remediation Due Date2022-03-24
Ransomware UseUnknown

Affected Products

canonical:ubuntu_linuxdebian:debian_linuxmozilla:firefoxmozilla:thunderbirdmozilla:thunderbird_esropensuse:opensuseredhat:enterprise_linux_desktopredhat:enterprise_linux_eusredhat:enterprise_linux_for_ibm_z_systemsredhat:enterprise_linux_for_ibm_z_systems_eusredhat:enterprise_linux_for_power_big_endianredhat:enterprise_linux_for_power_big_endian_eusredhat:enterprise_linux_for_scientific_computingredhat:enterprise_linux_serverredhat:enterprise_linux_server_ausredhat:enterprise_linux_server_eus_from_rhuiredhat:enterprise_linux_workstationredhat:gluster_storage_server_for_on-premise

Weaknesses (CWE)

CWE-665CWE-665

References

http://rhn.redhat.com/errata/RHSA-2013-0820.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2013-0821.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2013/dsa-2699(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/59858(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-1822-1(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-1823-1(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.mozilla.org/show_bug.cgi?id=866825(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.