Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-1670


The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 does not prevent acquisition of chrome privileges during calls to content level constructors, which allows remote attackers to bypass certain read-only restrictions and conduct cross-site scripting (XSS) attacks via a crafted web site.


Published

2013-05-16T11:45:30.777

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mozilla firefox ≤ 20.0.1 Yes
Application mozilla firefox 19.0 Yes
Application mozilla firefox 19.0.1 Yes
Application mozilla firefox 19.0.2 Yes
Application mozilla firefox 20.0 Yes
Application mozilla firefox 17.0 Yes
Application mozilla firefox 17.0.1 Yes
Application mozilla firefox 17.0.2 Yes
Application mozilla firefox 17.0.3 Yes
Application mozilla firefox 17.0.4 Yes
Application mozilla firefox 17.0.5 Yes
Application mozilla thunderbird ≤ 17.0.5 Yes
Application mozilla thunderbird 17.0 Yes
Application mozilla thunderbird 17.0.1 Yes
Application mozilla thunderbird 17.0.2 Yes
Application mozilla thunderbird 17.0.3 Yes
Application mozilla thunderbird 17.0.4 Yes
Application mozilla thunderbird_esr 17.0 Yes
Application mozilla thunderbird_esr 17.0.1 Yes
Application mozilla thunderbird_esr 17.0.2 Yes
Application mozilla thunderbird_esr 17.0.3 Yes
Application mozilla thunderbird_esr 17.0.4 Yes
Application mozilla thunderbird_esr 17.0.5 Yes

References