CVE-2013-1690

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jun 26, 2013
Updated: Dec 20, 2024
CWE ID 119

Summary

CVE-2013-1690 is a vulnerability affecting Mozilla Firefox versions prior to 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7. The issue involves improper handling of onreadystatechange events during page reloading. An attacker can exploit this vulnerability by creating a malicious website that triggers an application crash due to an attempt to execute data at an unmapped memory location. In severe cases, arbitrary code execution may be possible, leading to denial-of-service attacks or potential data compromise. Users are advised to update their browsers to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mozilla Firefox
  • Mozilla Thunderbird
  • SUSE Linux Enterprise Server
  • Mozilla Thunderbird Esr
  • Red Hat Enterprise Linux

Affected Vendors

  • Mozilla
  • Red Hat
  • Debian
  • SUSE Linux GmbH
  • Canonical System