4.3
CVE-2013-5614
- EPSS 2.35%
- Veröffentlicht 11.12.2013 15:55:12
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended sandbox restrictions via a crafted web site.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 19
Fedoraproject ≫ Fedora Version 20
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 12.10
Canonical ≫ Ubuntu Linux Version 13.04
Canonical ≫ Ubuntu Linux Version 13.10
Redhat ≫ Enterprise Linux Desktop Version 5.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Eus Version 6.5
Redhat ≫ Enterprise Linux Server Version 5.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Aus Version 6.5
Redhat ≫ Enterprise Linux Server Eus Version 6.5
Redhat ≫ Enterprise Linux Server Tus Version 6.5
Redhat ≫ Enterprise Linux Workstation Version 5.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
Suse ≫ Linux Enterprise Desktop Version 11 Update sp3
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwPlatform -
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwPlatform vmware
Suse ≫ Linux Enterprise Software Development Kit Version 11 Update sp3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.35% | 0.815 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-1021 Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://rhn.redhat.com/errata/RHSA-2013-1812.html
https://security.gentoo.org/glsa/201504-01
http://lists.fedoraproject.org/pipermail/package-announce/2013-December/123437.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124257.html
http://lists.opensuse.org/opensuse-updates/2013-12/msg00085.html
http://lists.opensuse.org/opensuse-updates/2013-12/msg00086.html
http://lists.opensuse.org/opensuse-updates/2013-12/msg00087.html
http://lists.opensuse.org/opensuse-updates/2014-01/msg00002.html
http://www.securitytracker.com/id/1029470
http://www.securitytracker.com/id/1029476
http://www.ubuntu.com/usn/USN-2052-1
http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00010.html
http://www.mozilla.org/security/announce/2013/mfsa2013-107.html
https://bugzilla.mozilla.org/show_bug.cgi?id=886262