Executive brief
Mozilla Firefox and Thunderbird fail to properly initialize data structures within the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions. This flaw allows remote attackers to disclose sensitive information from process memory via a specially crafted website.
Affected products
- Mozilla Firefox before 21.0
- Mozilla Firefox ESR 17.x before 17.0.6
- Mozilla Thunderbird before 17.0.6
- Mozilla Thunderbird ESR 17.x before 17.0.6
Timeline
- 2013-05-14: advisory: Mozilla Foundation Security Advisory MFSA2013-47 published.
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) Catalog.
- 2022-03-03: disclosed: NVD publication date.