Vulnerability Intelligence Report
Mozilla Firefox Information Disclosure Vulnerability
CVE-2013-1675
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
6.5
MEDIUM
Exploitability:2.9
Impact Score:3.6
EPSS Probability:6.70%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-665 ↗CWE-665 Improper Initialization
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| mozilla | firefox | all |
| mozilla | thunderbird | all |
| mozilla | thunderbird_esr | all |
| canonical | ubuntu_linux | 12.04, 12.10, 13.04 |
| debian | debian_linux | 7.0 |
| redhat | gluster_storage_server_for_on-premise | 2.1 |
| redhat | enterprise_linux_desktop | 5.0, 6.0 |
| redhat | enterprise_linux_eus | 5.9, 6.4 |
| redhat | enterprise_linux_for_ibm_z_systems | 5.0_s390x, 6.0_s390x |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 5.9_s390x, 6.4_s390x |
| redhat | enterprise_linux_for_power_big_endian | 5.0_ppc, 6.0_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 5.9_ppc, 6.4_ppc64 |
| redhat | enterprise_linux_for_scientific_computing | 6.0 |
| redhat | enterprise_linux_server | 5.0, 6.0 |
| redhat | enterprise_linux_server_aus | 5.9, 6.4 |
| redhat | enterprise_linux_server_eus_from_rhui | 5.9, 6.4 |
| redhat | enterprise_linux_workstation | 5.0, 6.0 |
| opensuse | opensuse | 12.2, 12.3 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Mozilla Corporation · Vendor · USA |
| Reserved | 2013-02-13T00:00:00 |
| Published | 2013-05-16T10:00:00 |
| Patch Date | 2013-05-14 |
| Last Updated | 2025-10-22T00:05:42 |
Community Chatter & Buzz