Vulnerability record · CVE-2013-1690 · published 26 June 2013
CVE-2013-1690: Mozilla Firefox and Thunderbird memory corruption via onreadystatechange handling
Mozilla · Firefox
Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7 and Thunderbird ESR 17.x before 17.0.7 mishandle onreadystatechange events combined with page reloading, causing execution of data at an unmapped memory location. This can crash the application or potentially allow arbitrary code execution when a victim views a crafted web page.
Description
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows remote code execution with user interaction, is listed in CISA KEV, and has a very high EPSS score, though exploitation requires a user to open crafted content.
What it is
Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7 and Thunderbird ESR 17.x before 17.0.7 mishandle onreadystatechange events combined with page reloading, causing execution of data at an unmapped memory location. This can crash the application or potentially allow arbitrary code execution when a victim views a crafted web page.
Impact
An attacker can crash the browser or mail client and may achieve arbitrary code execution in the context of the affected application. Successful code execution would give the attacker the privileges of the user running Firefox or Thunderbird.
Attack surface
Reached remotely over the network by luring a user to a crafted web site or message that triggers the onreadystatechange and reload sequence. No authentication is required, but user interaction (opening the page or content) is needed per the CVSS vector UI:R.
Exploitation
CVE-2013-1690 is listed in CISA KEV (added 2022-03-28) and has a high EPSS 30-day probability of 0.69021 (99.3rd percentile), indicating observed exploitation activity. No ransomware campaign use is documented.
What to do
- Upgrade Firefox to 22.0 or later and Firefox ESR to 17.0.7 or later; upgrade Thunderbird and Thunderbird ESR to 17.0.7 or later.
- Apply the vendor and distribution updates referenced in the Mozilla MFSA 2013-53 advisory and the Red Hat, Debian, Ubuntu, and openSUSE errata.
- If immediate patching is not possible, restrict browsing and mail rendering of untrusted content and disable JavaScript where feasible.
- Track KEV remediation due date (2022-04-18) and confirm all affected endpoints and servers are updated.
Detection
- Monitor for Firefox or Thunderbird crash reports and abnormal process terminations on endpoints running unpatched versions.
- Hunt for exploitation attempts via proxy, IDS, or web logs showing crafted pages that combine onreadystatechange handlers with forced reloads.
- Check asset inventories for Firefox versions below 22.0, Firefox ESR below 17.0.7, and Thunderbird below 17.0.7.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2013-1690 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-1690 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-1690), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.