EXPOSURES › CVE-2013-1675
CVE-2013-1675
HIGH ⌖ ON CISA KEV · EXPLOITEDA Firefox information disclosure vulnerability allowed remote attackers to read sensitive data from process memory via a crafted website.
The vulnerability stemmed from improper initialization of data structures in Firefox's SVG zoom event handling, enabling memory disclosure. DIB organizations must ensure their browsers are patched, as unpatched CVEs in widely used software like Firefox are a common attack vector for data exfiltration and can lead to compliance failures under NIST 800-171 if sensitive data is exposed.
Shame score — A known vulnerability in a widely deployed browser that was actively exploited in the wild (KEV) demonstrates a failure to patch critical software, leading to potential data exposure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
"Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site."