CVE-2013-1670
EXPLOITEDMozilla Firefox < 20.0.1 - XSS
Title source: ruleDescription
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 does not prevent acquisition of chrome privileges during calls to content level constructors, which allows remote attackers to bypass certain read-only restrictions and conduct cross-site scripting (XSS) attacks via a crafted web site.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/34363
References (17)
Scores
EPSS
0.2456
EPSS Percentile
96.1%
Details
VulnCheck KEV
2017-01-09
CWE
CWE-79
CWE-264
Status
published
Products (24)
mozilla/firefox
< 20.0.1
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
... and 14 more
Published
May 16, 2013
Tracked Since
Feb 18, 2026