cbcvebase.
CVE-2013-1690
published 2013-06-26

CVE-2013-1690: Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle…

PriorityP183high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-04-18
Exploited in the wild
EPSS
69.02%
99.3th percentile
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
mozillafirefox< 22.022.0
mozillafirefox>= 17.0 < 17.0.717.0.7
mozillathunderbird< 17.0.717.0.7
mozillathunderbird_esr>= 17.0 < 17.0.717.0.7
opensuseopensuse
opensuseopensuse
opensuseopensuse
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
redhatgluster_storage_server_for_on-premise
suselinux_enterprise_desktop
suselinux_enterprise_desktop
suselinux_enterprise_server

Detection & IOCsextracted from sources · hover to see the quote

bytes
\x64\xa1\x18\x00\x00\x00
  • Exploit is triggered via a specially crafted web page using onreadystatechange events combined with the window.stop() API, causing a use-after-free of a DocumentViewerImpl object. Monitor browser traffic for pages combining these two mechanisms.
  • Exploit was used in the wild in August 2013 targeting Tor Browser users. Inspect traffic from Tor Browser instances for exploitation attempts against Firefox 17.x.
  • ·The vulnerability cannot be exploited via email in Thunderbird or SeaMonkey because scripting is disabled in those contexts; exploitation risk is limited to browser or browser-like contexts.
  • ·The exploit sets EXITFUNC to 'process', meaning the payload terminates the entire Firefox process on exit rather than just the thread — post-exploitation forensics should account for process termination as a normal artifact.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_ubuntu10.0CRITICAL
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.