6.5

CVE-2013-1675

Warnung
Exploit
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version < 21.0
Mozilla ≫ Firefox Version >= 17.0 < 17.0.6
Mozilla ≫ Thunderbird Version < 17.0.6
Mozilla ≫ Thunderbird Esr Version >= 17.0 < 17.0.6
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 12.10
Canonical ≫ Ubuntu Linux Version 13.04
Debian ≫ Debian Linux Version 7.0
Redhat ≫ Enterprise Linux Eus Version 5.9
Redhat ≫ Enterprise Linux Eus Version 6.4
Opensuse ≫ Opensuse Version 12.2
Opensuse ≫ Opensuse Version 12.3

03.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Mozilla Firefox Information Disclosure Vulnerability

Schwachstelle

Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.7% 0.931
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CISA-ADP 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-665 Improper Initialization

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

http://www.debian.org/security/2013/dsa-2699
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.html
Third Party Advisory
Mailing List
http://rhn.redhat.com/errata/RHSA-2013-0820.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0821.html
Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2013:165
Broken Link
http://www.ubuntu.com/usn/USN-1822-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-1823-1
Third Party Advisory
http://www.mozilla.org/security/announce/2013/mfsa2013-47.html
Vendor Advisory
http://www.securityfocus.com/bid/59858
Third Party Advisory
Broken Link
VDB Entry
https://bugzilla.mozilla.org/show_bug.cgi?id=866825
Exploit
Issue Tracking
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16976
Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-1675
US Government Resource