CVE-2013-1675: Mozilla Firefox Information Disclosure Vulnerability
Medium severity, CVSS 6.5. Actively exploited: in CISA KEV since 2022-03-03. EPSS: 6.7% chance of exploitation in the next 30 days.
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 12.10 only; version 13.04 only
- Debian Debian Linux: version 7.0 only
- Mozilla Firefox: before 21.0 (fixed in 21.0); from 17.0, before 17.0.6 (fixed in 17.0.6)
- Mozilla Thunderbird: before 17.0.6 (fixed in 17.0.6)
- Mozilla Thunderbird ESR: from 17.0, before 17.0.6 (fixed in 17.0.6)
- Opensuse Opensuse: version 12.2 only; version 12.3 only
- Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Eus: version 5.9 only; version 6.4 only
- Red Hat Enterprise Linux For IBM Z Systems: version 5.0_s390x only; version 6.0_s390x only
- Red Hat Enterprise Linux For IBM Z Systems Eus: version 5.9_s390x only; version 6.4_s390x only
- Red Hat Enterprise Linux For Power Big Endian: version 5.0_ppc only; version 6.0_ppc64 only
- Red Hat Enterprise Linux For Power Big Endian Eus: version 5.9_ppc only; version 6.4_ppc64 only
- Red Hat Enterprise Linux For Scientific Computing: version 6.0 only
- Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Server Aus: version 5.9 only; version 6.4 only
- Red Hat Enterprise Linux Server Eus From Rhui: version 5.9 only; version 6.4 only
- Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only
- Red Hat Gluster Storage Server For On-Premise: version 2.1 only
Published 2013-05-16. Last modified 2026-06-16.