CVE-2013-1690

EUVD-2013-1717
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADPADP
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
𝑥
< 22.0
mozillafirefox
17.0 ≤
𝑥
< 17.0.7
mozillathunderbird
𝑥
< 17.0.7
mozillathunderbird_esr
17.0 ≤
𝑥
< 17.0.7
canonicalubuntu_linux
12.04
canonicalubuntu_linux
12.10
canonicalubuntu_linux
13.04
debiandebian_linux
7.0
redhatgluster_storage_server_for_on-premise
2.0
redhatenterprise_linux_desktop
5.0
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_eus
5.9
redhatenterprise_linux_eus
6.4
redhatenterprise_linux_server
5.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server_aus
5.9
redhatenterprise_linux_server_aus
6.4
redhatenterprise_linux_workstation
5.0
redhatenterprise_linux_workstation
6.0
opensuseopensuse
11.4
opensuseopensuse
12.2
opensuseopensuse
12.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
lucid
ignored
precise
Fixed 22.0+build1-0ubuntu0.12.04.1
released
quantal
Fixed 22.0+build1-0ubuntu0.12.10.1
released
raring
Fixed 22.0+build1-0ubuntu0.13.04.1
released
seamonkey
lucid
ignored
precise
dne
quantal
dne
raring
dne
thunderbird
lucid
ignored
precise
Fixed 17.0.7+build1-0ubuntu0.12.04.1
released
quantal
Fixed 17.0.7+build1-0ubuntu0.12.10.1
released
raring
Fixed 17.0.7+build1-0ubuntu0.13.04.1
released
xulrunner-1.9.2
lucid
ignored
precise
dne
quantal
dne
raring
dne
References