CVE-2013-1675

Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
mozillaCNA
---
---
CVEADP
---
---
CISA-ADPADP
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
mozillafirefox
𝑥
< 21.0
mozillafirefox
17.0 ≤
𝑥
< 17.0.6
mozillathunderbird
𝑥
< 17.0.6
mozillathunderbird_esr
17.0 ≤
𝑥
< 17.0.6
canonicalubuntu_linux
12.04
canonicalubuntu_linux
12.10
canonicalubuntu_linux
13.04
debiandebian_linux
7.0
redhatgluster_storage_server_for_on-premise
2.1
redhatenterprise_linux_desktop
5.0
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_eus
5.9
redhatenterprise_linux_eus
6.4
redhatenterprise_linux_for_ibm_z_systems
5.0_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems
6.0_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems_eus
5.9_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems_eus
6.4_s390x:_s390x
redhatenterprise_linux_for_power_big_endian
5.0_ppc:_ppc
redhatenterprise_linux_for_power_big_endian
6.0_ppc64:_ppc64
redhatenterprise_linux_for_power_big_endian_eus
5.9_ppc:_ppc
redhatenterprise_linux_for_power_big_endian_eus
6.4_ppc64:_ppc64
redhatenterprise_linux_for_scientific_computing
6.0
redhatenterprise_linux_server
5.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server_aus
5.9
redhatenterprise_linux_server_aus
6.4
redhatenterprise_linux_server_eus_from_rhui
5.9
redhatenterprise_linux_server_eus_from_rhui
6.4
redhatenterprise_linux_workstation
5.0
redhatenterprise_linux_workstation
6.0
opensuseopensuse
12.2
opensuseopensuse
12.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
raring
Fixed 21.0+build1-0ubuntu0.12.04.2
released
quantal
Fixed 21.0+build1-0ubuntu0.12.10.2
released
precise
Fixed 21.0+build1-0ubuntu0.12.04.3
released
lucid
ignored
seamonkey
raring
dne
quantal
dne
precise
dne
lucid
ignored
thunderbird
raring
Fixed 17.0.6+build1-0ubuntu0.13.04.1
released
quantal
Fixed 17.0.6+build1-0ubuntu0.12.10.1
released
precise
Fixed 17.0.6+build1-0ubuntu0.12.04.1
released
lucid
ignored
xulrunner-1.9.2
raring
dne
quantal
dne
precise
dne
lucid
ignored
References