CVE-2013-1690
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2013-1690 is a vulnerability affecting Mozilla Firefox versions prior to 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7. The issue involves improper handling of onreadystatechange events during page reloading. An attacker can exploit this vulnerability by creating a malicious website that triggers an application crash due to an attempt to execute data at an unmapped memory location. In severe cases, arbitrary code execution may be possible, leading to denial-of-service attacks or potential data compromise. Users are advised to update their browsers to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mozilla Firefox
- Mozilla Thunderbird
- SUSE Linux Enterprise Server
- Mozilla Thunderbird Esr
- Red Hat Enterprise Linux
Affected Vendors
- Mozilla
- Red Hat
- Debian
- SUSE Linux GmbH
- Canonical System