Mozilla: Execution of unmapped memory through onreadystatechange event (MFSA 2013-53)
Published Jun 26, 2013 ·Due Apr 18, 2022
8.8
HIGHCVSS 3.1
EPSS 69.02%
Description
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.
Affected products
No data.
Configuration 1
- < 22.0
- ≥ 17.0 · < 17.0.7
- < 17.0.7
- ≥ 17.0 · < 17.0.7
Configuration 2
- 12.04
- 12.10
- 13.04
Configuration 3
- 7.0
Configuration 4
- 2.0
- 5.0
- 6.0
- 5.9
- 6.4
- 5.0
- 6.0
- 5.9
- 6.4
- 5.0
- 6.0
Configuration 5
- 11.4
- 12.2
- 12.3
- 10
- 11
- 11
- 10
- 11
- 11
- 11
- 11
- 11
- 11
- 10
- 11
No data.
Red Hat Enterprise Linux 5
firefox-0:17.0.7-1.el5_9
Fixed · RHSA-2013:0981
Red Hat Enterprise Linux 5
thunderbird-0:17.0.7-1.el5_9
Fixed · RHSA-2013:0982
Red Hat Enterprise Linux 5
xulrunner-0:17.0.7-1.el5_9
Fixed · RHSA-2013:0981
Red Hat Enterprise Linux 6
firefox-0:17.0.7-1.el6_4
Fixed · RHSA-2013:0981
Red Hat Enterprise Linux 6
thunderbird-0:17.0.7-1.el6_4
Fixed · RHSA-2013:0982
Red Hat Enterprise Linux 6
xulrunner-0:17.0.7-1.el6_4
Fixed · RHSA-2013:0981
Red Hat Enterprise Linux 5
thunderbird
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | firefox-0:17.0.7-1.el5_9 | Fixed | RHSA-2013:0981 |
| Red Hat Enterprise Linux 5 | thunderbird-0:17.0.7-1.el5_9 | Fixed | RHSA-2013:0982 |
| Red Hat Enterprise Linux 5 | xulrunner-0:17.0.7-1.el5_9 | Fixed | RHSA-2013:0981 |
| Red Hat Enterprise Linux 6 | firefox-0:17.0.7-1.el6_4 | Fixed | RHSA-2013:0981 |
| Red Hat Enterprise Linux 6 | thunderbird-0:17.0.7-1.el6_4 | Fixed | RHSA-2013:0982 |
| Red Hat Enterprise Linux 6 | xulrunner-0:17.0.7-1.el6_4 | Fixed | RHSA-2013:0981 |
| Red Hat Enterprise Linux 5 | thunderbird | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Date Added
Mar 28, 2022
Patch Due
Apr 18, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (23 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 69.02% (0.69021) | 99.33th | v5 (v2026.06.15) |
| Jun 15, 2026 | 69.24% (0.69236) | 99.27th | v5 (v2026.06.15) |
| Mar 7, 2026 | 47.05% (0.47055) | 97.61th | v4 (v2025.03.14) |
| Sep 26, 2025 | 49.62% (0.49616) | 97.74th | v4 (v2025.03.14) |
| Jul 9, 2025 | 48.49% (0.48488) | 97.61th | v4 (v2025.03.14) |
| Jul 2, 2025 | 47.05% (0.47055) | 97.56th | v4 (v2025.03.14) |
| Mar 30, 2025 | 45.92% (0.45919) | 97.36th | v4 (v2025.03.14) |
| Mar 29, 2025 | 61.60% (0.61598) | 97.61th | v4 (v2025.03.14) |
| Mar 28, 2025 | 48.77% (0.48765) | 97.52th | v4 (v2025.03.14) |
| Mar 17, 2025 | 64.01% (0.64006) | 98.27th | v4 (v2025.03.14) |
| Dec 17, 2024 | 37.01% (0.37007) | 97.20th | v3 (v2023.03.01) |
| Jul 20, 2024 | 22.22% (0.22218) | 96.54th | v3 (v2023.03.01) |
| Jul 10, 2024 | 22.93% (0.22927) | 96.58th | v3 (v2023.03.01) |
| May 16, 2024 | 8.78% (0.08780) | 94.51th | v3 (v2023.03.01) |
| Nov 18, 2023 | 6.40% (0.06397) | 92.92th | v3 (v2023.03.01) |
| Sep 29, 2023 | 3.91% (0.03910) | 90.90th | v3 (v2023.03.01) |
| Aug 12, 2023 | 3.72% (0.03717) | 90.57th | v3 (v2023.03.01) |
| Jun 24, 2023 | 4.56% (0.04562) | 91.31th | v3 (v2023.03.01) |
| May 8, 2023 | 3.90% (0.03898) | 90.60th | v3 (v2023.03.01) |
| Mar 22, 2023 | 4.69% (0.04689) | 91.34th | v3 (v2023.03.01) |
| Mar 7, 2023 | 5.13% (0.05131) | 91.70th | v3 (v2023.03.01) |
| Mar 6, 2023 | 83.35% (0.83349) | 99.60th | v2 (v2022.01.01) |
| Feb 4, 2022 | 83.35% (0.83349) | 99.52th | v2 (v2022.01.01) |
References (23)
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0981.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0982.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.debian.org/security/2013/dsa-2716 vendor-advisoryx_refsource_DEBIANMailing ListThird Party Advisory
- http://www.debian.org/security/2013/dsa-2720 vendor-advisoryx_refsource_DEBIANMailing ListThird Party Advisory
- http://www.mozilla.org/security/announce/2013/mfsa2013-53.html x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/60778 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-1890-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-1891-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2013-1690 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=857883 x_refsource_CONFIRMIssue Tracking
- https://bugzilla.mozilla.org/show_bug.cgi?id=901365 x_refsource_CONFIRMIssue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=977602 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-1690
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-1690 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2013-1690
Change history (0)
No recorded changes yet.