CVE-2013-1687: XSS
The System Only Wrapper (SOW) and Chrome Object Wrapper (COW) implementations in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly restrict XBL user-defined functions, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges, or conduct cross-site scripting (XSS) attacks, via a crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1687?
CVE-2013-1687 has a high severity rating due to its potential to allow remote code execution.
How do I fix CVE-2013-1687?
To fix CVE-2013-1687, upgrade to a version of Firefox or Thunderbird that is 22.0 or later, or apply the latest security patches.
Which versions of software are affected by CVE-2013-1687?
CVE-2013-1687 affects Mozilla Firefox versions prior to 22.0, Firefox ESR 17.x before 17.0.7, and Thunderbird versions before 17.0.7.
What types of attacks can CVE-2013-1687 facilitate?
CVE-2013-1687 can facilitate remote attackers executing arbitrary code in the context of the user running the affected software.
Is there a specific update for CVE-2013-1687?
Yes, updating Firefox and Thunderbird to their latest versions that are not affected by CVE-2013-1687 will resolve the vulnerability.