peter bassill · operator
$ cve CVE-2013-1690 JSON

CVE-2013-1690 KEV EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 69% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-18.

Description

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS69.02% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-119
On CISA KEVyes — remediate by 2022-04-18
Public exploityes
Published2013-06-26
Last modified2026-06-16

CISA KEV

NameMozilla Firefox and Thunderbird Denial-of-Service Vulnerability
Added2022-03-28
Due2022-04-18
Vendor / productMozilla / Firefox and Thunderbird
Ransomware usenone reported

Affected (15)

VendorProduct
canonicalubuntu linux
debiandebian linux
mozillafirefox
mozillathunderbird
mozillathunderbird esr
opensuseopensuse
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux workstation
redhatgluster storage server for on-premise
suselinux enterprise desktop
suselinux enterprise server
suselinux enterprise software development kit

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD