EXPOSURES › CVE-2013-1690
CVE-2013-1690
HIGH ⌖ ON CISA KEV · EXPLOITEDA DoS vulnerability in Firefox and Thunderbird allowed remote attackers to cause denial-of-service or possibly execute malicious code via crafted websites.
This DoS vulnerability in Mozilla Firefox and Thunderbird allowed remote attackers to cause denial-of-service or possibly execute malicious code via crafted websites. DIB organizations should care because it highlights the risk of unpatched browser vulnerabilities that can lead to service disruption or potential code execution. Organizations must ensure their browsers are kept up-to-date with the latest security patches to mitigate such risks.
Shame score — The vulnerability was a known issue that could lead to DoS or possible code execution, but it was not a zero-day exploit and did not result in a mass data breach or ransomware attack.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.