Skip to content
COOEY

EXPOSURES › CVE-2013-1690

CVE-2013-1690

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-28 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2013-1690 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatched

A DoS vulnerability in Firefox and Thunderbird allowed remote attackers to cause denial-of-service or possibly execute malicious code via crafted websites.

This DoS vulnerability in Mozilla Firefox and Thunderbird allowed remote attackers to cause denial-of-service or possibly execute malicious code via crafted websites. DIB organizations should care because it highlights the risk of unpatched browser vulnerabilities that can lead to service disruption or potential code execution. Organizations must ensure their browsers are kept up-to-date with the latest security patches to mitigate such risks.

Shame score — The vulnerability was a known issue that could lead to DoS or possible code execution, but it was not a zero-day exploit and did not result in a mass data breach or ransomware attack.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.