CVE-2013-1690

Confirmed PUBLISHED

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly...

Mozilla · Firefox, Firefox ESR, Thunderbird, Thunderbird ESR
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.8 High

At a Glance

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.

metasploit cisa
CVE Published
Jun 26, 2013
Exploitation Reported
Mar 28, 2022
CVSS
8.8 High
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • USN-1890-1 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-1890-1
  • RHSA-2013:0982 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2013-0982.html
  • SUSE-SU-2013:1153 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011...
  • SUSE-SU-2013:1152 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010...
  • RHSA-2013:0981 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2013-0981.html
Show 12 more references
  • USN-1891-1 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-1891-1
  • openSUSE-SU-2013:1141 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004...
  • DSA-2716 debian.org · Vendor Advisory http://www.debian.org/security/2013/dsa-2716
  • openSUSE-SU-2013:1142 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005...
  • openSUSE-SU-2013:1140 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003...
  • DSA-2720 debian.org · Vendor Advisory http://www.debian.org/security/2013/dsa-2720
  • openSUSE-SU-2013:1143 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006...
  • oval:org.mitre.oval:def:16996 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...
  • 60778 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/60778
  • bugzilla.mozilla.org/show_bug.cgi bugzilla.mozilla.org · CVE Record https://bugzilla.mozilla.org/show_bug.cgi?id=857883
  • mozilla.org/security/announce/2013/mfsa2013-53.html mozilla.org · CVE Record http://www.mozilla.org/security/announce/2013/mfsa2013-53.html
  • bugzilla.mozilla.org/show_bug.cgi bugzilla.mozilla.org · CVE Record https://bugzilla.mozilla.org/show_bug.cgi?id=901365

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.