Skip to content
COOEY

EXPOSURES › CVE-2013-1675

CVE-2013-1675

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2013-1675 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

A Firefox information disclosure vulnerability allowed remote attackers to read sensitive data from process memory via a crafted website.

The vulnerability stemmed from improper initialization of data structures in Firefox's SVG zoom event handling, enabling memory disclosure. DIB organizations must ensure their browsers are patched, as unpatched CVEs in widely used software like Firefox are a common attack vector for data exfiltration and can lead to compliance failures under NIST 800-171 if sensitive data is exposed.

Shame score — A known vulnerability in a widely deployed browser that was actively exploited in the wild (KEV) demonstrates a failure to patch critical software, leading to potential data exposure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability allowed remote attackers to obtain sensitive information from process memory, indicating a significant security failure in Firefox's data structure initialization.
cooey ↗ severe-fallout -0.60
Vulnerability allowed remote attackers to obtain sensitive information from process memory, indicating a significant security failure in Firefox's data structure initialization.
"Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.