⚠ Actively exploited
Added to CISA KEV on 2022-03-28. Federal agencies required to patch by 2022-04-18. Required action: Apply updates per vendor instructions..

CVE-2013-1690

CWE-119Buffer Overflow11 documents9 sources
Severity
8.8HIGH
EPSS
47.1%
top 2.32%
CISA KEV
KEV
Added 2022-03-28
Due 2022-04-18
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJun 26
KEV addedMar 28
KEV dueApr 18
Latest updateMay 17
CISA Required Action: Apply updates per vendor instructions.

Description

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages11 packages

NVDmozilla/firefox17.017.0.7+1
NVDmozilla/thunderbird< 17.0.7
NVDmozilla/thunderbird_esr17.017.0.7
NVDopensuse/opensuse11.4, 12.2, 12.3+2

Also affects: Debian Linux 7.0, Ubuntu Linux 12.04, 12.10, 13.04, Enterprise Linux 5.9, 6.4

🔴Vulnerability Details

3
GHSA
GHSA-m5w3-m6g8-4mhf: Mozilla Firefox before 222022-05-17
CVEList
CVE-2013-1690: Mozilla Firefox before 222013-06-26
VulnCheck
Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability2013

💥Exploits & PoCs

1
Exploit-DB
Mozilla Firefox - onreadystatechange Event DocumentViewerImpl Use-After-Free (Metasploit)2013-08-08

📋Vendor Advisories

5
CISA
Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability2022-03-28
Ubuntu
Thunderbird vulnerabilities2013-06-26
Ubuntu
Firefox vulnerabilities2013-06-26
Red Hat
Mozilla: Execution of unmapped memory through onreadystatechange event (MFSA 2013-53)2013-06-25
Red Hat
mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)2012-04-17

💬Community

1
Bugzilla
CVE-2013-1690 Mozilla: Execution of unmapped memory through onreadystatechange event (MFSA 2013-53)2013-06-25