CVE-2013-1711

The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging access to an unprivileged object.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mozillaCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
VendorProductVersion
mozillaseamonkey
𝑥
≤ 2.20
mozillaseamonkey
2.0
mozillaseamonkey
2.0:alpha_1
mozillaseamonkey
2.0:alpha_2
mozillaseamonkey
2.0:alpha_3
mozillaseamonkey
2.0:beta_1
mozillaseamonkey
2.0:beta_2
mozillaseamonkey
2.0:rc1
mozillaseamonkey
2.0:rc2
mozillaseamonkey
2.0.1
mozillaseamonkey
2.0.2
mozillaseamonkey
2.0.3
mozillaseamonkey
2.0.4
mozillaseamonkey
2.0.5
mozillaseamonkey
2.0.6
mozillaseamonkey
2.0.7
mozillaseamonkey
2.0.8
mozillaseamonkey
2.0.9
mozillaseamonkey
2.0.10
mozillaseamonkey
2.0.11
mozillaseamonkey
2.0.12
mozillaseamonkey
2.0.13
mozillaseamonkey
2.0.14
mozillaseamonkey
2.1
mozillaseamonkey
2.1:alpha1
mozillaseamonkey
2.1:alpha2
mozillaseamonkey
2.1:alpha3
mozillaseamonkey
2.1:beta1
mozillaseamonkey
2.1:beta2
mozillaseamonkey
2.1:beta3
mozillaseamonkey
2.1:rc1
mozillaseamonkey
2.1:rc2
mozillaseamonkey
2.2
mozillaseamonkey
2.2:beta1
mozillaseamonkey
2.2:beta2
mozillaseamonkey
2.2:beta3
mozillaseamonkey
2.3
mozillaseamonkey
2.3:beta1
mozillaseamonkey
2.3:beta2
mozillaseamonkey
2.3:beta3
mozillaseamonkey
2.3.1
mozillaseamonkey
2.3.2
mozillaseamonkey
2.3.3
mozillaseamonkey
2.4
mozillaseamonkey
2.4:beta1
mozillaseamonkey
2.4:beta2
mozillaseamonkey
2.4:beta3
mozillaseamonkey
2.4.1
mozillaseamonkey
2.5
mozillaseamonkey
2.5:beta1
mozillaseamonkey
2.5:beta2
mozillaseamonkey
2.5:beta3
mozillaseamonkey
2.5:beta4
mozillaseamonkey
2.6
mozillaseamonkey
2.6:beta1
mozillaseamonkey
2.6:beta2
mozillaseamonkey
2.6:beta3
mozillaseamonkey
2.6:beta4
mozillaseamonkey
2.6.1
mozillaseamonkey
2.7
mozillaseamonkey
2.7:beta1
mozillaseamonkey
2.7:beta2
mozillaseamonkey
2.7:beta3
mozillaseamonkey
2.7:beta4
mozillaseamonkey
2.7:beta5
mozillaseamonkey
2.7.1
mozillaseamonkey
2.7.2
mozillaseamonkey
2.8
mozillaseamonkey
2.8:beta1
mozillaseamonkey
2.8:beta2
mozillaseamonkey
2.8:beta3
mozillaseamonkey
2.8:beta4
mozillaseamonkey
2.8:beta5
mozillaseamonkey
2.8:beta6
mozillaseamonkey
2.9
mozillaseamonkey
2.9:beta1
mozillaseamonkey
2.9:beta2
mozillaseamonkey
2.9:beta3
mozillaseamonkey
2.9:beta4
mozillaseamonkey
2.9.1
mozillaseamonkey
2.10
mozillaseamonkey
2.10:beta1
mozillaseamonkey
2.10:beta2
mozillaseamonkey
2.10:beta3
mozillaseamonkey
2.10.1
mozillaseamonkey
2.11
mozillaseamonkey
2.11:beta1
mozillaseamonkey
2.11:beta2
mozillaseamonkey
2.11:beta3
mozillaseamonkey
2.11:beta4
mozillaseamonkey
2.11:beta5
mozillaseamonkey
2.11:beta6
mozillaseamonkey
2.12
mozillaseamonkey
2.12:beta1
mozillaseamonkey
2.12:beta2
mozillaseamonkey
2.12:beta3
mozillaseamonkey
2.12:beta4
mozillaseamonkey
2.12:beta5
mozillaseamonkey
2.12:beta6
mozillaseamonkey
2.12.1
mozillaseamonkey
2.13
mozillaseamonkey
2.13:beta1
mozillaseamonkey
2.13:beta2
mozillaseamonkey
2.13:beta3
mozillaseamonkey
2.13:beta4
mozillaseamonkey
2.13:beta5
mozillaseamonkey
2.13:beta6
mozillaseamonkey
2.13.1
mozillaseamonkey
2.13.2
mozillaseamonkey
2.14
mozillaseamonkey
2.14:beta1
mozillaseamonkey
2.14:beta2
mozillaseamonkey
2.14:beta3
mozillaseamonkey
2.14:beta4
mozillaseamonkey
2.14:beta5
mozillaseamonkey
2.15
mozillaseamonkey
2.15:beta1
mozillaseamonkey
2.15:beta2
mozillaseamonkey
2.15:beta3
mozillaseamonkey
2.15:beta4
mozillaseamonkey
2.15:beta5
mozillaseamonkey
2.15:beta6
mozillaseamonkey
2.15.1
mozillaseamonkey
2.15.2
mozillaseamonkey
2.16
mozillaseamonkey
2.16:beta1
mozillaseamonkey
2.16:beta2
mozillaseamonkey
2.16:beta3
mozillaseamonkey
2.16:beta4
mozillaseamonkey
2.16:beta5
mozillaseamonkey
2.16.1
mozillaseamonkey
2.16.2
mozillaseamonkey
2.17
mozillaseamonkey
2.17:beta1
mozillaseamonkey
2.17:beta2
mozillaseamonkey
2.17:beta3
mozillaseamonkey
2.17:beta4
mozillaseamonkey
2.17.1
mozillaseamonkey
2.18:beta1
mozillaseamonkey
2.18:beta2
mozillaseamonkey
2.18:beta3
mozillaseamonkey
2.18:beta4
mozillaseamonkey
2.19
mozillaseamonkey
2.19:beta1
mozillaseamonkey
2.19:beta2
mozillaseamonkey
2.20:beta1
mozillaseamonkey
2.20:beta2
mozillafirefox
𝑥
≤ 22.0
mozillafirefox
19.0
mozillafirefox
19.0.1
mozillafirefox
19.0.2
mozillafirefox
20.0
mozillafirefox
20.0.1
mozillafirefox
21.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
raring
Fixed 23.0+build2-0ubuntu0.13.04.1
released
quantal
Fixed 23.0+build2-0ubuntu0.12.10.1
released
precise
Fixed 23.0+build2-0ubuntu0.12.04.1
released
lucid
ignored