5
CVSSv2

CVE-2013-1695

Published: 26/06/2013 Updated: 19/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Mozilla Firefox prior to 22.0 does not properly implement certain DocShell inheritance behavior for the sandbox attribute of an IFRAME element, which allows remote malicious users to bypass intended access restrictions via a FRAME element within an IFRAME element.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 20.0

mozilla firefox 20.0.1

mozilla firefox

mozilla firefox 19.0.1

mozilla firefox 19.0.2

mozilla firefox 19.0

Vendor Advisories

USN-1890-1 introduced a regression in Firefox ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2013-57 Sandbox restrictions not applied to nested frame elements Announced June 25, 2013 Reporter Bob Owen Impact Low Products Firefox, SeaMonkey Fixed in ...