V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2013-5614
DEB
Medium

Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing…

CVSS
5.1
Medium
EPSS
0.02
p81
Published
2013-01-01
Updated
2013-01-01
Description

Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended sandbox restrictions via a crafted web site.

Tags · CWE
CWE-1021
CAPEC-103
CAPEC-181
CAPEC-222
CAPEC-504
CAPEC-506
CAPEC-587
CAPEC-654
Affected products
Enterprise_linux_desktopEnterprise_linux_eusEnterprise_linux_serverEnterprise_linux_server_ausEnterprise_linux_server_eusEnterprise_linux_server_tusEnterprise_linux_workstation
CVSS vector
AV:N/AC:H/Au:N/C:P/I:P/A:P
Timeline
2013-01-01
Published
2013-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.024 · p81
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-504 · CWE-1021
└ via CAPEC-654 · CWE-1021
└ via CAPEC-654 · CWE-1021
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
firefoxTracked
firefoxTracked
iceweaselTracked
thunderbirdTracked
thunderbirdTracked
enterprise_linux_desktop*Tracked
enterprise_linux_eus*Tracked
enterprise_linux_server*Tracked
enterprise_linux_server_aus*Tracked
enterprise_linux_server_eus*Tracked
enterprise_linux_server_tus*Tracked
enterprise_linux_workstation*Tracked
fedora*Tracked
firefox*Tracked
linux_enterprise_desktop*Tracked
linux_enterprise_server*Tracked
linux_enterprise_software_development_kit*Tracked
opensuse*Tracked
seamonkey*Tracked
solaris*Tracked
Showing first 20 of 21
Source databases
DEB
CVE
RED