CVE-2013-1693
The SVG filter implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to read pixel values, and possibly bypass the Same Origin Policy and read text from a different domain, by observing timing differences in execution of filter code.
- Affected products
- Centos, Firefox Esr, Firefox, Red Hat, Suse, Thunderbird, Thunderbird Esr
- Mozilla Firefox
- ≤ 21.0, 19.0, 19.0.1, 19.0.2, 20.0, 20.0.1
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 3.7% (89th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2013-06-26
CVE-2013-1693 at NVD
No indexed exploits for CVE-2013-1693 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2013-1693 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.