SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-0793

Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 do not ensure the correctness of the address bar during history navigation, which allows remote…

MEDIUM 4.3EPSS 2.19%

Does this matter?

Lower severity and a low EPSS score (2.19%). Track it; it rarely justifies an emergency change on its own.

Description

Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 do not ensure the correctness of the address bar during history navigation, which allows remote attackers to conduct cross-site scripting (XSS) attacks or phishing attacks by leveraging control over navigation timing.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
2.19% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
mozilla/firefox · mozilla/thunderbird · mozilla/thunderbird esr · mozilla/seamonkey
Source
security@mozilla.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.