CISA KEV · catalog date Mar 3, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2013-1675
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for…
Exploited in the wild (CISA KEV since Mar 3, 2022). NVD reports CVSS 3.1 6.5. EPSS estimates 6.7% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
- State
- PUBLISHED
- Published
- May 16, 2013
- Updated
- Oct 22, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmozillaOriginal evidence ↗
Record text: Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
Inspect raw assertion
- Field
container- Value
- Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Mozilla Firefox Information Disclosure Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Mozilla Firefox Information Disclosure Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 6.7% probability · 93.41th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.066960000000; percentile 0.934120000000
FIRST EPSS · score date Aug 27, 2026 · 93.4th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
Inspect raw assertion
- Field
container- Value
- Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
Mozilla Firefox Information Disclosure Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Mozilla Firefox Information Disclosure Vulnerability
6.7% probability · 93.41th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.066960000000; percentile 0.934120000000
Applicability
Cited product scope
Grouped from 5 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
19 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2Linked exactInspect raw assertions
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e2076871-2e80-4605-a470-a41c1a8ec7ee
cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
efaa48d9-beb4-4e49-ad50-325c262d46d9
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cb66db75-2b16-4ebf-9b93-ce49d8086e41
product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertion
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
16f59a04-14cf-49e2-9973-645477ea09da
product-07fd419647bc4be85f7cd99fb6db991c405f59f4526c86f98007cccadd88fb6bLinked exactInspect raw assertions
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 17.0; through excluding 17.0.6
- Match ID
00db2973-f49d-4fb9-9692-9c8ed7e5a4a9
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 21.0
- Match ID
dbe90626-80e9-42af-b3d6-1bc1a198134a
product-148c720470a65e23ffba2cd2146b70004a125bb02def92b1d58b670632c22fffLinked exactInspect raw assertion
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- through excluding 17.0.6
- Match ID
c932e9fe-70eb-472a-b4a8-8947e89087ab
product-3326f518ef0c292d88ea8c85738611645c419920c61894e11dd069ba594bafafLinked exactInspect raw assertion
cpe:2.3:a:mozilla:thunderbird_esr:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 17.0; through excluding 17.0.6
- Match ID
83cbb1da-7360-4268-876f-7e69ba2a9c69
product-66ca8198d1887ac9754d1aad85d76f1edfc54c873eb2cd9bedf566863f5e07bdLinked exactInspect raw assertions
cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d806a17e-b8f9-466d-807d-3f1e77603dc8
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dfbf430b-0832-44b0-aa0e-ba9e467f7668
product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5aeLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ee249e1b-a1fd-4e08-aa71-a0e1f10ffe97
cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
133aafa7-af42-4d7b-8822-aa2e85611bf5
product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_eus:6.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8a8e07b7-3739-4beb-88f8-c7f62431e889
cpe:2.3:o:redhat:enterprise_linux_eus:5.9:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6252e88c-27ff-420d-a64a-c34124cf7e6a
product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0bLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:6.0_s390x:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c84eaae7-0249-4ea1-b8d3-e039b03acdc3
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:5.0_s390x:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
90be67da-1f52-43dd-8610-8f8d414c0189
product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fdLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:6.4_s390x:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8dc5b615-5b9e-40ec-98de-9fd16dac9fea
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:5.9_s390x:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cf88f74a-2bd3-4ae1-b0f0-f1d6868da154
product-fd0893ef7253031c8ee72effb6fcc65181f9b3f5e01f8f48b6a6ab89a31380a9Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:6.0_ppc64:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6d8d654f-2442-4ea0-af89-6ac2cd214772
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:5.0_ppc:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
29bbf1ac-f31f-4251-8054-0d89a8e6e990
product-c09e1a6c06a60f75d4f5a3a91108bcb8e8b7418b4d0bcbe56608e9eba3cd934bLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:5.9_ppc:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8535d453-1063-4d47-803a-db09d1d8eea5
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:6.4_ppc64:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fe4e4888-46c6-4de0-b591-a7fb914f5238
product-d22fc88b6b85afc426c8220428110aecfb39a59d3b7ddf5757cf39cb9f5feb2fLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
634c23ac-ac9c-43f4-bed8-1c720816d5e3
product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9deaLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
54d669d4-6d7e-449d-80c1-28fa44f06ffe
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9bbcd86a-e6c7-4444-9d74-f861084090f0
product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aaeLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_server_aus:5.9:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
92c9f1c4-55b0-426d-bb5e-01372c23af97
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
af83bb87-b203-48f9-9d06-48a5fe399050
product-097fec49e5158a1d0b63bee3ca4ae728479ffb7c9d82ad18502ae5089b0585e3Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_server_eus_from_rhui:5.9:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
54f65e6d-500c-4c13-9eb8-fea1b6912117
cpe:2.3:o:redhat:enterprise_linux_server_eus_from_rhui:6.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
afbd04ed-609b-4b67-8c4f-beb8fd6260f9
product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9Linked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d0ac5cd5-6e58-433c-9eb3-6dfe5656463e
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e5ed5807-55b7-47c5-97a6-03233f4fbc3a
product-5fb86209cb28a171a615b064839fb8a647f4262a91b6043cb733d29a3026f76eLinked exactInspect raw assertion
cpe:2.3:a:redhat:gluster_storage_server_for_on-premise:2.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ec489f35-07f1-4c3e-80b9-78f0689bc54b
Affected-product evidence
Accepted scope and product mapping
18 canonical links · 1 source-reported links
vendor-a8002e9a4c58b83fa97f47fe42903a60facd8770768e9b325e288d873b8b8255 · product-07fd419647bc4be85f7cd99fb6db991c405f59f4526c86f98007cccadd88fb6b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3631d115-0ffb-4088-a135-cf4915828caa5c35c650-d747-4ede-bc5a-6d2cc66bedacvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-097fec49e5158a1d0b63bee3ca4ae728479ffb7c9d82ad18502ae5089b0585e3
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0acf7b94-4367-465a-b0b4-0fd378f9a8d7f0958c6c-6fb2-481c-9614-545f35ebfa33vendor-a8002e9a4c58b83fa97f47fe42903a60facd8770768e9b325e288d873b8b8255 · product-148c720470a65e23ffba2cd2146b70004a125bb02def92b1d58b670632c22fff
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
938a9ad7-a7ae-45f6-9d7e-e6a5af3df653vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
705df97d-17c9-439e-88d2-ecfb5da023cfa49d381a-20c2-49c6-b741-fd3895b1aab0vendor-a8002e9a4c58b83fa97f47fe42903a60facd8770768e9b325e288d873b8b8255 · product-3326f518ef0c292d88ea8c85738611645c419920c61894e11dd069ba594bafaf
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
dec16c34-c5a3-4b05-9d06-594be993d153vendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
eeaf20ea-3f1e-4960-a2e1-0eb9ad29b667vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-5fb86209cb28a171a615b064839fb8a647f4262a91b6043cb733d29a3026f76e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3293ec3f-f7f1-436b-8399-4c5a4119b536vendor-f98e1750e4b030e2bb71130d14421ff255427227a8b696c92978cf6c77fc265d · product-66ca8198d1887ac9754d1aad85d76f1edfc54c873eb2cd9bedf566863f5e07bd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
97ae8f2f-91f2-47cb-8ef0-115274a74ced9beb6cda-9269-4793-b75e-5f39c2cccb58vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3ff6a35c-14d1-41f0-8a26-33fe650c194ca99bc680-1b01-4108-8ba2-8d1fac786fa3vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
29f87407-e7a7-4291-8abc-e6933c9a6a83ed9a2430-3333-4703-b2e5-f7f846cd2a77vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9dea
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b6d28175-29d0-4a57-8521-1ac9e62f6ebcba347a89-0292-49d7-a360-ca267292fbdavendor-c57a6167e95991f72f9616ac32b40463ac13c5f4929fcce3efc058b09a445b54 · product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6746c43d-a394-4218-ab17-a5c164243c5eedf94fd7-f65a-4143-880b-06e49f570c5af4c53d05-6f76-494e-ac33-583cf275ea36vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d8ff9187-e34f-4c7d-a998-a0fb79a7a089f71bd993-3ffd-439e-9398-31cb9a83ea92vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-c09e1a6c06a60f75d4f5a3a91108bcb8e8b7418b4d0bcbe56608e9eba3cd934b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0234d49e-35f3-4761-a363-a9bfb9ccc4651044be20-d9ad-4aab-8470-16b4e17b9e77vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-d22fc88b6b85afc426c8220428110aecfb39a59d3b7ddf5757cf39cb9f5feb2f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e49d06a2-2f90-432c-94de-9a7380002ea4vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5ae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0c5828fc-16d8-487f-b531-bd0365ae9b019843f3e8-a821-476f-8573-34027d22b8b4vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
36f7a166-2125-45f8-8771-b5187401a2985e995a99-e2e7-4397-a83a-ddfb801a15c9vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-fd0893ef7253031c8ee72effb6fcc65181f9b3f5e01f8f48b6a6ab89a31380a9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0308a562-db76-40ca-bf1a-6ac2851589f3ec4fbb15-b87d-4db7-a8a2-37b88767cc7cCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f39984b2-a4bf-4e5a-a5b1-f4caaf1bb777Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NAV:N/AC:M/Au:N/C:P/I:N/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N- Validation
- Valid match
- Recomputed
- 6.5
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.