← Back

CVE-2013-5598

nvd nist
Published: Oct 30, 2013Modified: Apr 29, 2026

JSON object

Loading...
8.3
Vector
AV:N/AC:M/Au:N/C:C/I:P/A:P
Exploitability: 8.6 / Impact: 8.5
Source: NVD

Description

PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.

Affected (13)

Products: Mozilla: Firefox
1 product
Firefox
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 24.0.1
Version 24.0.2
Version 24.0
Configuration B
10 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Up to 24.0
Version 19.0.1
Version 19.0.2
Version 19.0
Version 20.0.1
Version 20.0
Version 21.0
Version 22.0
Version 23.0.1
Version 23.0

Related CWEs

Timeline

No history available yet.