Evidence dossier

CVE-2013-1690

CVE-2013-1690

78.694.9Priority evidence range
As known Jul 21, 2026, 8:13 AM UTCgen-409cbd0c

Normalized restatement

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.

State
PUBLISHED
Published
Jun 26, 2013
Updated
Oct 22, 2025
Evidence coverage
85%
CISA KEVCatalog member

Apply updates per vendor instructions.

FIRST EPSS69.02%

2026-07-18 · v2026.06.15 · percentile 99.3%

Source stateNo scored conflict

Distinct CVSS assessments remain side by side; none are averaged.

Source comparison

Who said what

CISA-ADPindependent enrichment
container

CISA ADP Vulnrichment

CVEderivative copy
container

CVE Program Container

mozillaoriginal assertion
container

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.

CISA KEVoriginal assertion
observed_exploitation

Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

FIRST EPSSoriginal assertion
model_probability

Probability 0.690210000000; percentile 0.992750000000

Applicability

Cited product scope

Trace impact →
34Underlying assertions
15Canonical products
34Target assertions
0Constraint assertions

Grouped from 5 configuration nodes in this exact generation. Visual grouping does not establish asset exposure or common root cause.

Identity source boundaries
  • cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

16 scope groups

mozilla · source assertedn/an/aDirect source scope
[{"status": "affected", "version": "n/a"}]
unknown
NVD CPE · OPERATING SYSTEMcanonicalubuntu_linuxVulnerable target · 3 assertions
Version 12.04; Version 12.10; Version 13.04Canonical identity product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2linked exact
supported
Inspect 3 returned assertions
  1. cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    efaa48d9-beb4-4e49-ad50-325c262d46d9
  2. cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e2076871-2e80-4605-a470-a41c1a8ec7ee
  3. cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cb66db75-2b16-4ebf-9b93-ce49d8086e41
NVD CPE · OPERATING SYSTEMdebiandebian_linuxVulnerable target · 1 assertions
Version 7.0Canonical identity product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447elinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    16f59a04-14cf-49e2-9973-645477ea09da
NVD CPE · APPLICATIONmozillafirefoxVulnerable target · 2 assertions
Any version (unconstrained) (>= 17.0, < 17.0.7); Any version (unconstrained) (< 22.0)Canonical identity product-07fd419647bc4be85f7cd99fb6db991c405f59f4526c86f98007cccadd88fb6blinked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 22.0
    Match ID
    b0321165-fb26-4e37-b9ec-e09ff46034b4
  2. cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 17.0; through excluding 17.0.7
    Match ID
    56fcde03-ff73-45ae-8100-44bd50c4bd27
NVD CPE · APPLICATIONmozillathunderbirdVulnerable target · 1 assertions
Any version (unconstrained) (< 17.0.7)Canonical identity product-148c720470a65e23ffba2cd2146b70004a125bb02def92b1d58b670632c22ffflinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    through excluding 17.0.7
    Match ID
    945d0c7e-e76b-4e80-a78e-8fc59e0579e6
NVD CPE · APPLICATIONmozillathunderbird_esrVulnerable target · 1 assertions
Any version (unconstrained) (>= 17.0, < 17.0.7)Canonical identity product-3326f518ef0c292d88ea8c85738611645c419920c61894e11dd069ba594bafaflinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:a:mozilla:thunderbird_esr:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 17.0; through excluding 17.0.7
    Match ID
    d30b82f9-f16d-48c8-bfc4-1f4fa628b9e2
NVD CPE · OPERATING SYSTEMopensuseopensuseVulnerable target · 3 assertions
Version 11.4; Version 12.2; Version 12.3Canonical identity product-66ca8198d1887ac9754d1aad85d76f1edfc54c873eb2cd9bedf566863f5e07bdlinked exact
supported
Inspect 3 returned assertions
  1. cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    de554781-1eb9-446e-911f-6c11970c47f4
  2. cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d806a17e-b8f9-466d-807d-3f1e77603dc8
  3. cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dfbf430b-0832-44b0-aa0e-ba9e467f7668
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_desktopVulnerable target · 2 assertions
Version 5.0; Version 6.0Canonical identity product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5aelinked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    133aafa7-af42-4d7b-8822-aa2e85611bf5
  2. cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ee249e1b-a1fd-4e08-aa71-a0e1f10ffe97
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_eusVulnerable target · 2 assertions
Version 5.9; Version 6.4Canonical identity product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378linked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:redhat:enterprise_linux_eus:6.4:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8a8e07b7-3739-4beb-88f8-c7f62431e889
  2. cpe:2.3:o:redhat:enterprise_linux_eus:5.9:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6252e88c-27ff-420d-a64a-c34124cf7e6a
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_serverVulnerable target · 2 assertions
Version 5.0; Version 6.0Canonical identity product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9dealinked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9bbcd86a-e6c7-4444-9d74-f861084090f0
  2. cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    54d669d4-6d7e-449d-80c1-28fa44f06ffe
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_server_ausVulnerable target · 2 assertions
Version 5.9; Version 6.4Canonical identity product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aaelinked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:redhat:enterprise_linux_server_aus:6.4:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    af83bb87-b203-48f9-9d06-48a5fe399050
  2. cpe:2.3:o:redhat:enterprise_linux_server_aus:5.9:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    92c9f1c4-55b0-426d-bb5e-01372c23af97
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_workstationVulnerable target · 2 assertions
Version 5.0; Version 6.0Canonical identity product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9linked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e5ed5807-55b7-47c5-97a6-03233f4fbc3a
  2. cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d0ac5cd5-6e58-433c-9eb3-6dfe5656463e
NVD CPE · APPLICATIONredhatgluster_storage_server_for_on-premiseVulnerable target · 1 assertions
Version 2.0Canonical identity product-5fb86209cb28a171a615b064839fb8a647f4262a91b6043cb733d29a3026f76elinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:a:redhat:gluster_storage_server_for_on-premise:2.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    59d47e43-886e-4114-96a2-dbe719ea3a89
NVD CPE · OPERATING SYSTEMsuselinux_enterprise_desktopVulnerable target · 3 assertions
Version 10; Version 11Canonical identity product-908c58b965f5cdd7f6621821fd6c68d62c5a5ce89de01a9e91af7286e0b17d41linked exact
supported
Inspect 3 returned assertions
  1. cpe:2.3:o:suse:linux_enterprise_desktop:10:sp4:*:*:-:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4339de06-19fb-4b8e-b6ae-3495f605ad05
  2. cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3ed68add-bbda-4485-bc76-58f011d72311
  3. cpe:2.3:o:suse:linux_enterprise_desktop:11:sp2:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    00720d8c-3ff3-4b1c-b74b-91f01a544399
NVD CPE · OPERATING SYSTEMsuselinux_enterprise_serverVulnerable target · 7 assertions
Version 10; Version 11Canonical identity product-4f2240e45c4385f8980643ce838561b90551012dc317022ee66a7d71a9db8e28linked exact
supported
Inspect 7 returned assertions
  1. cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:-:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e534c201-bcc5-473c-aaa7-aab97ceb5437
  2. cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:ltss:-:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7f4af9ec-7c74-40c3-a1ba-82b80c4a7ee0
  3. cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:-:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    88d6e858-fd8f-4c55-b7d5-ceeda2bba898
  4. cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:vmware:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    db4d6749-81a1-41d7-bf4f-1c45a7f49a22
  5. cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:ltss:vmware:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    db9bbc2e-7d91-4879-898a-520d2d758d1b
  6. cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:-:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d1d7b467-58dd-45f1-9f1f-632620df072a
  7. cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2470c6e8-2024-4cf5-9982-cff50e88eae9
NVD CPE · OPERATING SYSTEMsuselinux_enterprise_software_development_kitVulnerable target · 2 assertions
Version 10; Version 11Canonical identity product-bd4950335ff1f3f03b9dd6fa5c596f7c67c9ea6d150272de074ec3767af3532alinked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp4:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    436ef2ed-fdbb-4b64-8ec4-33c3e4253f06
  2. cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp3:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2f7f8866-dead-44d1-ab10-21ee611aa026

Assessments

CVSS by origin

8.8
nvd@nist.govCVSS 3.1 · role PrimaryCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
9.3
nvd@nist.govCVSS 2.0 · role PrimaryAV:N/AC:M/Au:N/C:C/I:C/A:C
8.8
134c704f-9b21-4f2e-91b3-4a467353bcc0CVSS 3.1 · role SecondaryCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
8.8
CISA-ADPCVSS 3.1 · role unknownCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Limitations and unknowns

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
  • NVD-carried upstream facts remain derivative and are not independent corroboration.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Factor D remains unknown because WC-03 has not converted canonical CPE mappings into generation-bound mapping obligations; canonical identity alone does not score applicability.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.