CVE-2013-1675

CVE Published 2013-05-16
Related CWE(s) CWE-665: Improper Initialization, CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
Related Vendor(s) redhat, canonical, mozilla, opensuse, debian
Related Product(s) gluster_storage_server_for_on-premise, enterprise_linux_for_scientific_computing, opensuse, enterprise_linux_for_power_big_endian_eus, firefox, enterprise_linux_desktop, enterprise_linux_workstation, enterprise_linux_for_power_big_endian, enterprise_linux_eus, debian_linux, thunderbird_esr, ubuntu_linux, enterprise_linux_server_eus_from_rhui, thunderbird, enterprise_linux_server_aus, enterprise_linux_for_ibm_z_systems, firefox_esr, enterprise_linux_server, enterprise_linux_for_ibm_z_systems_eus
Exploitation Reported (CISA KEV) 2022-03-03
CVSS 3 Base Score 6.5 (MEDIUM)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References