VulnerabilityModified
CVE-2013-1729
The WebGL implementation in Mozilla Firefox before 24.0, when NVIDIA graphics drivers are used on Mac OS X, allows remote attackers to obtain desktop-screenshot data by reading from a CANVAS element.
LOW 2.6EPSS 1.23%
Does this matter?
Lower severity and a low EPSS score (1.23%). Track it; it rarely justifies an emergency change on its own.
Description
The WebGL implementation in Mozilla Firefox before 24.0, when NVIDIA graphics drivers are used on Mac OS X, allows remote attackers to obtain desktop-screenshot data by reading from a CANVAS element.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
- EPSS
- 1.23% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- mozilla/firefox
- Source
- security@mozilla.org
References
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115907.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116610.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/117526.html
- http://www.mozilla.org/security/announce/2013/mfsa2013-86.htmlVendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=879656
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/115907.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116610.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/117526.html
- http://www.mozilla.org/security/announce/2013/mfsa2013-86.htmlVendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=879656
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.