← Vulnerability feed

Vulnerability record · CVE-2013-1690 · published 26 June 2013

CVE-2013-1690: Mozilla Firefox and Thunderbird memory corruption via onreadystatechange handling

Mozilla · Firefox

Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7 and Thunderbird ESR 17.x before 17.0.7 mishandle onreadystatechange events combined with page reloading, causing execution of data at an unmapped memory location. This can crash the application or potentially allow arbitrary code execution when a victim views a crafted web page.

8.8 CVSS 3.1 High CISA KEV since 28 Mar 2022 EPSS 69% · top 0.7% CWE-119 · Memory buffer overflow
8.8CVSS 3.1 base score, v2 9.3
69%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
15Affected product versions listed by NVD
35References
16 Jun 2026Last modified by NVD

Description

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw allows remote code execution with user interaction, is listed in CISA KEV, and has a very high EPSS score, though exploitation requires a user to open crafted content.

What it is

Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7 and Thunderbird ESR 17.x before 17.0.7 mishandle onreadystatechange events combined with page reloading, causing execution of data at an unmapped memory location. This can crash the application or potentially allow arbitrary code execution when a victim views a crafted web page.

Impact

An attacker can crash the browser or mail client and may achieve arbitrary code execution in the context of the affected application. Successful code execution would give the attacker the privileges of the user running Firefox or Thunderbird.

Attack surface

Reached remotely over the network by luring a user to a crafted web site or message that triggers the onreadystatechange and reload sequence. No authentication is required, but user interaction (opening the page or content) is needed per the CVSS vector UI:R.

Exploitation

CVE-2013-1690 is listed in CISA KEV (added 2022-03-28) and has a high EPSS 30-day probability of 0.69021 (99.3rd percentile), indicating observed exploitation activity. No ransomware campaign use is documented.

What to do

  • Upgrade Firefox to 22.0 or later and Firefox ESR to 17.0.7 or later; upgrade Thunderbird and Thunderbird ESR to 17.0.7 or later.
  • Apply the vendor and distribution updates referenced in the Mozilla MFSA 2013-53 advisory and the Red Hat, Debian, Ubuntu, and openSUSE errata.
  • If immediate patching is not possible, restrict browsing and mail rendering of untrusted content and disable JavaScript where feasible.
  • Track KEV remediation due date (2022-04-18) and confirm all affected endpoints and servers are updated.

Detection

  • Monitor for Firefox or Thunderbird crash reports and abnormal process terminations on endpoints running unpatched versions.
  • Hunt for exploitation attempts via proxy, IDS, or web logs showing crafted pages that combine onreadystatechange handlers with forced reloads.
  • Check asset inventories for Firefox versions below 22.0, Firefox ESR below 17.0.7, and Thunderbird below 17.0.7.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2013-1690 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.

Affected products

15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html Mailing ListThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0981.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0982.html Third Party Advisory
http://www.debian.org/security/2013/dsa-2716 Mailing ListThird Party Advisory
http://www.debian.org/security/2013/dsa-2720 Mailing ListThird Party Advisory
http://www.mozilla.org/security/announce/2013/mfsa2013-53.html Vendor Advisory
http://www.securityfocus.com/bid/60778 Broken LinkThird Party AdvisoryVDB Entry
http://www.ubuntu.com/usn/USN-1890-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-1891-1 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=857883 Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=901365 Issue Tracking
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996 Broken Link
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00003.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00004.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00006.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00010.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00011.html Mailing ListThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0981.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0982.html Third Party Advisory
http://www.debian.org/security/2013/dsa-2716 Mailing ListThird Party Advisory
http://www.debian.org/security/2013/dsa-2720 Mailing ListThird Party Advisory
http://www.mozilla.org/security/announce/2013/mfsa2013-53.html Vendor Advisory
http://www.securityfocus.com/bid/60778 Broken LinkThird Party AdvisoryVDB Entry
http://www.ubuntu.com/usn/USN-1890-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-1891-1 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=857883 Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=901365 Issue Tracking
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16996 Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-1690 US Government Resource

Track CVE-2013-1690 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed10.0CVE-2019-11708Mozilla Firefox and Thunderbird sandbox escape via Prompt:Open IPC validation flawThe Prompt:Open IPC message between child and parent processes does not sufficiently vet its parameters, letting a compromised child process cause th…KEVEPSS 56%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed

Source: NIST National Vulnerability Database (record CVE-2013-1690), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.