{"id":"CVE-2013-1675","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-1675","summary":"Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale…","details":"Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.","published":"2013-05-16T10:00:00.000Z","modified":"2025-10-22T00:05:42.585Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"},"epss":{"score":0.06696,"percentile":0.93412,"asOf":"2026-08-27"},"cisaKev":{"dateAdded":"2022-03-03","dueDate":"2022-03-24","knownRansomwareCampaignUse":false},"exploitsKnown":2,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.debian.org/security/2013/dsa-2699"},{"type":"ADVISORY","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2013:165"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html"},{"type":"WEB","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=866825"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-1823-1"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2013-0821.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.html"},{"type":"WEB","url":"http://www.mozilla.org/security/announce/2013/mfsa2013-47.html"},{"type":"WEB","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16976"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2013-0820.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/59858"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-1822-1"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-1675"}],"provenance":{"sources":["OSV.dev","NVD","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2025-10-22T00:05:42.585Z"}}