CVE-2013-0792: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 1.4% chance of exploitation in the next 30 days.

Mozilla Firefox before 20.0 and SeaMonkey before 2.17, when gfx.color_management.enablev4 is used, do not properly handle color profiles during PNG rendering, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a grayscale PNG image.

Affected products

  • Mozilla Firefox: up to and including 19.0.2; version 19.0 only; version 19.0.1 only
  • Mozilla Seamonkey: up to and including 2.17; version 2.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; …

Published 2013-04-03. Last modified 2026-06-16.