← Back to browse · API

CVE-2013-1675

Severity
MEDIUM
CVSS
6.5
EPSS
0.06696
Risk score
53.34
CISA KEV
Yes
PoC
No
Published
2013-05-16
Modified
2025-10-22
First seen
2026-08-07
Aliases
EUVD-2013-1702, GHSA-7CV2-F4F9-VW96
Products
Mozilla:Firefox, n/a:n/a n/a
Sources
euvd EUVD-2013-1702
cisa.gov CVE-2013-1675

Description

Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

References