CVE-2013-1675
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
Mozilla Firefox and Thunderbird versions before 21.0 don't properly initialize certain memory structures when handling SVG zoom events, allowing attackers to read sensitive data from the browser's memory through a malicious website.
Uninitialized data structures in nsDOMSVGZoomEvent's mPreviousScale and mNewScale functions permit information disclosure via memory leakage. An attacker can craft a malicious SVG-containing webpage to trigger zoom events and access uninitialized heap memory containing sensitive data. This requires user interaction (visiting a crafted site) and affects Firefox <21.0 and Thunderbird <17.0.6.
The full analysis of this CVE is available in Portuguese →