CVE-2013-1697

Priority
Description
The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR
17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x
before 17.0.7 does not properly restrict use of DefaultValue for method
calls, which allows remote attackers to execute arbitrary JavaScript code
with chrome privileges via a crafted web site that triggers use of a
user-defined (1) toString or (2) valueOf method.
Assigned-to
chrisccoulson
Notes
Package
Upstream:released (22.0)
Package
Upstream:needs-triage
Package
Priority: Low
Upstream:released (17.0.7)
Package
Upstream:needs-triage
More Information

Updated: 2020-03-18 22:11:58 UTC (commit 2ea7df7bd1e69e1e489978d2724a936eb3faa1b8)