CVE-2013-1670

CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 89.39 % (99th)
89.39% Progress
Affected Products 4
Advisories 10

The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 does not prevent acquisition of chrome privileges during calls to content level constructors, which allows remote attackers to bypass certain read-only restrictions and conduct cross-site scripting (XSS) attacks via a crafted web site.

Weaknesses
CWE-264
Permissions, Privileges, and Access Controls
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2013-05-16 11:45:30
(11 years ago)
Updated Date
2017-09-19 01:36:09
(7 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 20.0.1 and prior versions cpe:2.3:a:mozilla:firefox <= 20.0.1
  Mozilla Firefox 19.0 cpe:2.3:a:mozilla:firefox:19.0
  Mozilla Firefox 19.0.1 cpe:2.3:a:mozilla:firefox:19.0.1
  Mozilla Firefox 19.0.2 cpe:2.3:a:mozilla:firefox:19.0.2
  Mozilla Firefox 20.0 cpe:2.3:a:mozilla:firefox:20.0

Configuration #2

    CPE23 From Up To
  Mozilla Firefox Esr 17.0 cpe:2.3:a:mozilla:firefox_esr:17.0
  Mozilla Firefox Esr 17.0.1 cpe:2.3:a:mozilla:firefox_esr:17.0.1
  Mozilla Firefox Esr 17.0.2 cpe:2.3:a:mozilla:firefox_esr:17.0.2
  Mozilla Firefox Esr 17.0.3 cpe:2.3:a:mozilla:firefox_esr:17.0.3
  Mozilla Firefox Esr 17.0.4 cpe:2.3:a:mozilla:firefox_esr:17.0.4
  Mozilla Firefox Esr 17.0.5 cpe:2.3:a:mozilla:firefox_esr:17.0.5

Configuration #3

    CPE23 From Up To
  Mozilla Thunderbird 17.0.5 and prior versions cpe:2.3:a:mozilla:thunderbird <= 17.0.5
  Mozilla Thunderbird 17.0 cpe:2.3:a:mozilla:thunderbird:17.0
  Mozilla Thunderbird 17.0.1 cpe:2.3:a:mozilla:thunderbird:17.0.1
  Mozilla Thunderbird 17.0.2 cpe:2.3:a:mozilla:thunderbird:17.0.2
  Mozilla Thunderbird 17.0.3 cpe:2.3:a:mozilla:thunderbird:17.0.3
  Mozilla Thunderbird 17.0.4 cpe:2.3:a:mozilla:thunderbird:17.0.4

Configuration #4

    CPE23 From Up To
  Mozilla Thunderbird Esr 17.0 cpe:2.3:a:mozilla:thunderbird_esr:17.0
  Mozilla Thunderbird Esr 17.0.1 cpe:2.3:a:mozilla:thunderbird_esr:17.0.1
  Mozilla Thunderbird Esr 17.0.2 cpe:2.3:a:mozilla:thunderbird_esr:17.0.2
  Mozilla Thunderbird Esr 17.0.3 cpe:2.3:a:mozilla:thunderbird_esr:17.0.3
  Mozilla Thunderbird Esr 17.0.4 cpe:2.3:a:mozilla:thunderbird_esr:17.0.4
  Mozilla Thunderbird Esr 17.0.5 cpe:2.3:a:mozilla:thunderbird_esr:17.0.5
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...