CVE-2013-1693
published 2013-06-26CVE-2013-1693: The SVG filter implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
3.74%
88.7th percentile
The SVG filter implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to read pixel values, and possibly bypass the Same Origin Policy and read text from a different domain, by observing timing differences in execution of filter code.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| mozilla | firefox | < 28.0 | 28.0 |
| mozilla | firefox | <= 21.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 24.0 < 24.4 | 24.4 |
| mozilla | seamonkey | < 2.25 | 2.25 |
| mozilla | thunderbird | < 24.4 | 24.4 |
| mozilla | thunderbird | <= 17.0.6 | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_ubuntu10.0CRITICAL
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rw38-97rx-85hc: The SVG filter implementation in Mozilla Firefox before 22
ghsa_unreviewed·2022-05-17
CVE-2013-1693 [MEDIUM] GHSA-rw38-97rx-85hc: The SVG filter implementation in Mozilla Firefox before 22
The SVG filter implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to read pixel values, and possibly bypass the Same Origin Policy and read text from a different domain, by observing timing differences in execution of filter code.
GHSA
GHSA-5656-j8pw-q247: The SVG filter implementation in Mozilla Firefox before 28
ghsa_unreviewed·2022-05-13·CVSS 4.3
CVE-2014-1505 [MEDIUM] CWE-200 GHSA-5656-j8pw-q247: The SVG filter implementation in Mozilla Firefox before 28
The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the Same Origin Policy and read text from a different domain, via a timing attack involving feDisplacementMap elements, a related issue to CVE-2013-1693.
Red Hat
Mozilla: SVG filters information disclosure through feDisplacementMap (MFSA 2014-28)
vendor_redhat·2014-03-18·CVSS 4.3
CVE-2014-1505 [MEDIUM] Mozilla: SVG filters information disclosure through feDisplacementMap (MFSA 2014-28)
Mozilla: SVG filters information disclosure through feDisplacementMap (MFSA 2014-28)
The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the Same Origin Policy and read text from a different domain, via a timing attack involving feDisplacementMap elements, a related issue to CVE-2013-1693.
Ubuntu
Firefox regression
vendor_ubuntu·2013-07-03·CVSS 10.0
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: USN-1890-1 introduced a regression in Firefox.
USN-1890-1 fixed vulnerabilities in Firefox. This update introduced a
regression which sometimes resulted in Firefox using the wrong network
proxy settings. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple memory safety issues were discovered in Firefox. If the user were
tricked into opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2013-1682, CVE-2013-1683)
Abhishek Arya discovered multiple use-after-free bugs. If the user were
tricked into opening a specially crafted page, an attac
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2013-06-26·CVSS 10.0
CVE-2013-1682 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple memory safety issues were discovered in Thunderbird. If the user
were tricked into opening a specially crafted message with scripting
enabled, an attacker could possibly exploit these to cause a denial of
service via application crash, or potentially execute arbitrary code with
the privileges of the user invoking Thunderbird. (CVE-2013-1682)
Abhishek Arya discovered multiple use-after-free bugs. If the user were
tricked into opening a specially crafted message with scripting enabled,
an attacker could possibly exploit these to execute arbitrary code with
the privileges of the user invoking Thunderbird. (CVE-2013-1684,
CVE-2013-1685, CVE-2013-1686)
Mariusz Mlynski discovered that user
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-06-26·CVSS 10.0
CVE-2013-1682 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple memory safety issues were discovered in Firefox. If the user were
tricked into opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2013-1682, CVE-2013-1683)
Abhishek Arya discovered multiple use-after-free bugs. If the user were
tricked into opening a specially crafted page, an attacker could possibly
exploit these to execute arbitrary code with the privileges of the user
invoking Firefox. (CVE-2013-1684, CVE-2013-1685, CVE-2013-1686)
Mariusz Mlynski discovered that user defined
Red Hat
Mozilla: SVG filters can lead to information disclosure (MFSA 2013-55)
vendor_redhat·2013-06-25·CVSS 4.3
CVE-2013-1693 [MEDIUM] Mozilla: SVG filters can lead to information disclosure (MFSA 2013-55)
Mozilla: SVG filters can lead to information disclosure (MFSA 2013-55)
The SVG filter implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to read pixel values, and possibly bypass the Same Origin Policy and read text from a different domain, by observing timing differences in execution of filter code.
Package: thunderbird (Red Hat Enterprise Linux 5) - Affected
No detection rules found.
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0981.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0982.htmlhttp://www.debian.org/security/2013/dsa-2716http://www.debian.org/security/2013/dsa-2720http://www.mozilla.org/security/announce/2013/mfsa2013-55.htmlhttp://www.securityfocus.com/bid/60787http://www.ubuntu.com/usn/USN-1890-1http://www.ubuntu.com/usn/USN-1891-1https://bugzilla.mozilla.org/show_bug.cgi?id=711043https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17075http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0981.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0982.htmlhttp://www.debian.org/security/2013/dsa-2716http://www.debian.org/security/2013/dsa-2720http://www.mozilla.org/security/announce/2013/mfsa2013-55.htmlhttp://www.securityfocus.com/bid/60787http://www.ubuntu.com/usn/USN-1890-1http://www.ubuntu.com/usn/USN-1891-1https://bugzilla.mozilla.org/show_bug.cgi?id=711043https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17075
2013-06-26
Published