Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0...
Moderate severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Jul 16, 2024
Description
Published by the National Vulnerability Database
May 16, 2013
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Jul 16, 2024
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
References