Junglewise Threat Intelligence

CVE-2013-1675: Mozilla Firefox Information Disclosure Vulnerability

CVE-2013-1675 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2022-03-03

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Thunderbird fail to properly initialize data structures within the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions. This flaw allows remote attackers to disclose sensitive information from process memory via a specially crafted website.

Affected products

  • Mozilla Firefox before 21.0
  • Mozilla Firefox ESR 17.x before 17.0.6
  • Mozilla Thunderbird before 17.0.6
  • Mozilla Thunderbird ESR 17.x before 17.0.6

Timeline

  • 2013-05-14: advisory: Mozilla Foundation Security Advisory MFSA2013-47 published.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) Catalog.
  • 2022-03-03: disclosed: NVD publication date.

Related threats