CVE-2013-1690 - Mozilla Firefox and Thunderbird
AI Vulnerability ContextMozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory locat...
Overview
A source-backed snapshot of this vulnerability.
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2013-1690
- Vendor/project
- Mozilla
- Product
- Firefox and Thunderbird
- Vulnerability name
- Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability
- Date added
- 2022-03-28
- Due date
- 2022-04-18
- Known ransomware campaign use
- Unknown
- CVSS v3
- 8.8
Exploit context
What the vulnerability is about.
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.
Source evidence
Original public records and references for this page.
Original source
Original source links
Open the public records and source datasets used for this page.
