cbcvebase.
CVE-2013-1675
published 2013-05-16

CVE-2013-1675: Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data…

PriorityP272medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
6.70%
93.2th percentile
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
mozillafirefox< 21.021.0
mozillafirefox>= 17.0 < 17.0.617.0.6
mozillathunderbird< 17.0.617.0.6
mozillathunderbird_esr>= 17.0 < 17.0.617.0.6
opensuseopensuse
opensuseopensuse
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_power_big_endian
redhatenterprise_linux_for_power_big_endian
redhatenterprise_linux_for_power_big_endian_eus
redhatenterprise_linux_for_power_big_endian_eus
redhatenterprise_linux_for_scientific_computing
redhatenterprise_linux_server
redhatenterprise_linux_server

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered via a crafted web site targeting uninitialized DOMSVGZoomEvent functions (nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale); monitor for SVGZoom event abuse in browser traffic
  • Thunderbird is not exploitable via email because scripting is disabled; focus detection efforts on browser and browser-like contexts
  • Reference Mozilla Security Advisory MFSA 2013-47 for patch and indicator context; unpatched Firefox < 21.0 and ESR < 17.0.6 are vulnerable
  • ·Exploitation leads to uninitialized memory disclosure and a potentially exploitable crash; not a remote code execution primitive by itself but can leak sensitive process memory

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vulncheck6.5MEDIUM
cisa6.5MEDIUM
vendor_ubuntu10.0CRITICAL
vendor_redhat6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.