CVE-2013-0792: Mozilla Firefox
Medium severity, CVSS 4.3. EPSS: 1.4% chance of exploitation in the next 30 days.
Mozilla Firefox before 20.0 and SeaMonkey before 2.17, when gfx.color_management.enablev4 is used, do not properly handle color profiles during PNG rendering, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a grayscale PNG image.
Affected products
- Mozilla Firefox: up to and including 19.0.2; version 19.0 only; version 19.0.1 only
- Mozilla Seamonkey: up to and including 2.17; version 2.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; …
Published 2013-04-03. Last modified 2026-06-16.