4.3
CVSSv2

CVE-2013-1698

Published: 26/06/2013 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The getUserMedia permission implementation in Mozilla Firefox prior to 22.0 references the URL of a top-level document instead of the URL of a specific page, which makes it easier for remote malicious users to trick users into permitting camera or microphone access via a crafted web site that uses IFRAME elements.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 19.0

mozilla firefox 19.0.1

mozilla firefox 19.0.2

mozilla firefox 20.0

mozilla firefox 20.0.1

mozilla firefox

Vendor Advisories

USN-1890-1 introduced a regression in Firefox ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2013-60 getUserMedia permission dialog incorrectly displays location Announced June 25, 2013 Reporter Matt Wobensmith Impact Moderate Products Firefox Fixed in ...
The getUserMedia permission implementation in Mozilla Firefox before 220 references the URL of a top-level document instead of the URL of a specific page, which makes it easier for remote attackers to trick users into permitting camera or microphone access via a crafted web site that uses IFRAME elements ...