CVE-2013-1675: Mozilla Firefox Information Disclosure Vulnerability
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
Other sources
Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1675?
CVE-2013-1675 has a severity rating that allows remote attackers to exploit it for potential privilege escalation.
How do I fix CVE-2013-1675?
To fix CVE-2013-1675, users should upgrade to Mozilla Firefox versions 21.0 or later, or to Firefox ESR 17.0.6 or later.
Which versions of software are affected by CVE-2013-1675?
CVE-2013-1675 affects Mozilla Firefox versions before 21.0 and Firefox ESR 17.x before 17.0.6, as well as Thunderbird versions before 17.0.6.
What type of vulnerability is CVE-2013-1675?
CVE-2013-1675 is a vulnerability related to improper initialization of data structures in Mozilla products.
Can CVE-2013-1675 be exploited remotely?
Yes, CVE-2013-1675 can potentially be exploited by remote attackers.