Umbra Wiki cve cve/CVE-2013-1690
Back to wiki

CVE-2013-1690 — Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

provenance: imported · CVE: CVE-2013-1690

CVE-2013-1690: Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Mozilla
Product Firefox and Thunderbird
Date added 2022-03-28
Due date 2022-04-18
Ransomware campaign use Unknown

Description

Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2013-1690

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2013-1690
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog