8.3
CVSSv2

CVE-2013-5598

Published: 30/10/2013 Updated: 19/09/2017
CVSS v2 Base Score: 8.3 | Impact Score: 8.5 | Exploitability Score: 8.6
VMScore: 739
Vector: AV:N/AC:M/Au:N/C:C/I:P/A:P

Vulnerability Summary

PDF.js in Mozilla Firefox prior to 25.0 and Firefox ESR 24.x prior to 24.1 does not properly handle the appending of an IFRAME element, which allows remote malicious users to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox esr 24.0.1

mozilla firefox esr 24.0.2

mozilla firefox esr 24.0

mozilla firefox 21.0

mozilla firefox 20.0.1

mozilla firefox 19.0.2

mozilla firefox 19.0.1

mozilla firefox 23.0

mozilla firefox 19.0

mozilla firefox 22.0

mozilla firefox

mozilla firefox 20.0

mozilla firefox 23.0.1

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2013-99 Security bypass of PDFjs checks using iframes Announced October 29, 2013 Reporter Cody Crews Impact High Products Firefox, Firefox ESR Fixed in ...