← Back

CVE-2013-1695

nvd nist
Published: Jun 26, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Mozilla Firefox before 22.0 does not properly implement certain DocShell inheritance behavior for the sandbox attribute of an IFRAME element, which allows remote attackers to bypass intended access restrictions via a FRAME element within an IFRAME element.

Affected (6)

Products: Mozilla: Firefox
1 product
Firefox
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Up to 21.0
Version 19.0.1
Version 19.0.2
Version 19.0
Version 20.0.1
Version 20.0

Related CWEs

Timeline

No history available yet.