CISA KEV 정보
| 취약점명 | Mozilla Firefox Information Disclosure Vulnerability |
|---|---|
| 설명 | Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. |
| 조치사항 | Apply updates per vendor instructions. |
| 랜섬웨어 캠페인 악용 | Unknown |
| CWE | CWE-119 |
| 등록일 (KEV) | 2022-03-03 |
| 조치 기한 | 2022-03-24 |
| 추가 참고 | https://nvd.nist.gov/vuln/detail/CVE-2013-1675 |
NVD 상세 정보
CVSS v3.1: 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NCVSS v2.0: 4.3
AV:N/AC:M/Au:N/C:P/I:N/A:N설명: Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
CWE: CWE-665 | CWE-665
참조
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html [Mailing List, Third Party Advisory]
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html [Mailing List, Third Party Advisory]
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html [Mailing List, Third Party Advisory]
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00006.html [Mailing List, Third Party Advisory]
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00008.html [Mailing List, Third Party Advisory]
- http://rhn.redhat.com/errata/RHSA-2013-0820.html [Third Party Advisory]
- http://rhn.redhat.com/errata/RHSA-2013-0821.html [Third Party Advisory]
- http://www.debian.org/security/2013/dsa-2699 [Mailing List]
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:165 [Broken Link]
- http://www.mozilla.org/security/announce/2013/mfsa2013-47.html [Vendor Advisory]
- http://www.securityfocus.com/bid/59858 [Broken Link, Third Party Advisory, VDB Entry]
- http://www.ubuntu.com/usn/USN-1822-1 [Third Party Advisory]
- http://www.ubuntu.com/usn/USN-1823-1 [Third Party Advisory]
- https://bugzilla.mozilla.org/show_bug.cgi?id=866825 [Exploit, Issue Tracking]
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16976 [Broken Link]
- ... 외 16건
This product uses the NVD API but is not endorsed or certified by the NVD.