{
  "id": "CVE-2013-1675",
  "url": "https://spydr.io/cve/CVE-2013-1675",
  "published": "2013-05-16T11:45:30.877Z",
  "modified": "2026-06-16T23:51:53.300Z",
  "score": 6.5,
  "severity": "medium",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
  "score_source": "NVD",
  "epss": 0.06696,
  "epss_percentile": 0.93745,
  "exploited": true,
  "kev": {
    "added": "2022-03-03",
    "due": "2022-03-24",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "Mozilla Firefox Information Disclosure Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2013-1675"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "mozilla",
    "canonical",
    "debian",
    "redhat",
    "opensuse"
  ],
  "products": [
    "mozilla firefox",
    "mozilla thunderbird",
    "mozilla thunderbird esr",
    "canonical ubuntu linux",
    "debian linux",
    "redhat gluster storage server for on-premise",
    "redhat enterprise linux desktop",
    "redhat enterprise linux eus",
    "redhat enterprise linux for ibm z systems",
    "redhat enterprise linux for ibm z systems eus",
    "redhat enterprise linux for power big endian",
    "redhat enterprise linux for power big endian eus",
    "redhat enterprise linux for scientific computing",
    "redhat enterprise linux server",
    "redhat enterprise linux server aus",
    "redhat enterprise linux server eus from rhui",
    "redhat enterprise linux workstation",
    "opensuse"
  ],
  "cwes": [
    "CWE-665"
  ],
  "description": "Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 6.5,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2013-0820.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2013-0821.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.debian.org/security/2013/dsa-2699",
      "tags": [
        "Mailing List"
      ]
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2013:165",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://www.mozilla.org/security/announce/2013/mfsa2013-47.html",
      "tags": [
        "Vendor Advisory"
      ]
    },
    {
      "url": "http://www.securityfocus.com/bid/59858",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1822-1",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1823-1",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=866825",
      "tags": [
        "Exploit",
        "Issue Tracking"
      ]
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16976",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-1675",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2013-1675",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
