⚠ Actively exploited
Added to CISA KEV on 2022-03-28. Federal agencies required to patch by 2022-04-18. Required action: Apply updates per vendor instructions..
CVE-2013-1690
Severity
8.8HIGH
EPSS
47.1%
top 2.32%
CISA KEV
KEV
Added 2022-03-28
Due 2022-04-18
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedJun 26
KEV addedMar 28
KEV dueApr 18
Latest updateMay 17
CISA Required Action: Apply updates per vendor instructions.
Description
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages11 packages
Also affects: Debian Linux 7.0, Ubuntu Linux 12.04, 12.10, 13.04, Enterprise Linux 5.9, 6.4
🔴Vulnerability Details
3💥Exploits & PoCs
1Exploit-DB▶
Mozilla Firefox - onreadystatechange Event DocumentViewerImpl Use-After-Free (Metasploit)↗2013-08-08
📋Vendor Advisories
5Red Hat
▶
💬Community
1Bugzilla▶
CVE-2013-1690 Mozilla: Execution of unmapped memory through onreadystatechange event (MFSA 2013-53)↗2013-06-25