CVE-2013-1737: Medium severity mozilla thunderbird vulnerability
Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1737?
CVE-2013-1737 has been assigned a medium severity rating, indicating potential exploitation risks to affected software.
How do I fix CVE-2013-1737?
To fix CVE-2013-1737, update to the latest versions of Mozilla Firefox, Thunderbird, or SeaMonkey that resolve this vulnerability.
Which versions are affected by CVE-2013-1737?
CVE-2013-1737 affects Mozilla Firefox versions before 24.0, Thunderbird versions before 24.0, and SeaMonkey versions before 2.21.
Can CVE-2013-1737 lead to exploitation?
Yes, CVE-2013-1737 could allow remote attackers to bypass intended security restrictions, posing a risk of exploitation.
Does CVE-2013-1737 affect mobile browsers?
No, CVE-2013-1737 specifically affects desktop versions of Mozilla software, not mobile browsers.