Junglewise Threat Intelligence

CVE-2013-1690: Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

CVE-2013-1690 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-28

Technologies: Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Thunderbird, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Thunderbird fail to properly handle onreadystatechange events during page reloads. This flaw allows remote attackers to trigger an application crash or potentially execute arbitrary code by inducing an attempt to execute data at an unmapped memory location via a crafted website.

Affected products

  • Mozilla Firefox before 22.0
  • Mozilla Firefox ESR 17.x before 17.0.7
  • Mozilla Thunderbird before 17.0.7
  • Mozilla Thunderbird ESR 17.x before 17.0.7

Timeline

  • 2013-06-25: disclosed: Mozilla Foundation Security Advisory MFSA2013-53 published
  • 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-28: exploited: CISA confirms exploitation in the wild

Related threats