CVE-2013-1688
- EPSS 1.2%
- Veröffentlicht 26.06.2013 03:19:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Profiler implementation in Mozilla Firefox before 22.0 parses untrusted data during UI rendering, which allows user-assisted remote attackers to execute arbitrary JavaScript code via a crafted web site.
CVE-2013-1690
- EPSS 49.48%
- Veröffentlicht 26.06.2013 03:19:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause...
CVE-2013-1692
- EPSS 0.73%
- Veröffentlicht 26.06.2013 03:19:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not prevent the inclusion of body data in an XMLHttpRequest HEAD request, which makes it easier for remote attackers to ...
CVE-2013-1693
- EPSS 0.44%
- Veröffentlicht 26.06.2013 03:19:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The SVG filter implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to read pixel values, and possibly bypass the Same Origin Policy a...
CVE-2013-1694
- EPSS 2.11%
- Veröffentlicht 26.06.2013 03:19:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The PreserveWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly handle the lack of a wrapper, which allows remote attackers to caus...
- EPSS 0.16%
- Veröffentlicht 26.06.2013 03:19:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 22.0 does not properly implement certain DocShell inheritance behavior for the sandbox attribute of an IFRAME element, which allows remote attackers to bypass intended access restrictions via a FRAME element within an IFRAME el...
- EPSS 0.43%
- Veröffentlicht 26.06.2013 03:19:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 22.0 does not properly enforce the X-Frame-Options protection mechanism, which allows remote attackers to conduct clickjacking attacks via a crafted web site that uses the HTTP server push feature with multipart responses.
CVE-2013-1697
- EPSS 1.91%
- Veröffentlicht 26.06.2013 03:19:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote atta...
CVE-2013-1698
- EPSS 0.33%
- Veröffentlicht 26.06.2013 03:19:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The getUserMedia permission implementation in Mozilla Firefox before 22.0 references the URL of a top-level document instead of the URL of a specific page, which makes it easier for remote attackers to trick users into permitting camera or microphone...
- EPSS 0.37%
- Veröffentlicht 26.06.2013 03:19:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Internationalized Domain Name (IDN) display algorithm in Mozilla Firefox before 22.0 does not properly handle the .com, .name, and .net top-level domains, which allows remote attackers to spoof the address bar via unspecified homograph characters...