CVE-2013-1697 (retired)

Priority
Description
The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR
17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x
before 17.0.7 does not properly restrict use of DefaultValue for method
calls, which allows remote attackers to execute arbitrary JavaScript code
with chrome privileges via a crafted web site that triggers use of a
user-defined (1) toString or (2) valueOf method.
Assigned-to
chrisccoulson
Package
Upstream:released (22.0)
Package
Upstream:needs-triage
Package
Priority: Low
Upstream:released (17.0.7)
Package
Upstream:needs-triage
More Information

Updated: 2019-03-26 12:07:18 UTC (commit ccdecfcf0fead22bd291e5f4ea745a46872dcb15)