CVE-2013-5598
Last modified
CVE-2013-5598 is a vulnerability of currently unknown severity. PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.. EPSS estimates a 2.94% chance of exploitation in the next 30 days.
Description
PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 24.0 |
| Mozilla | Firefox | 24.0.1 |
| Mozilla | Firefox | 24.0.2 |
| Mozilla | Firefox | <= 24.0 |
| Mozilla | Firefox | 19.0 |
| Mozilla | Firefox | 19.0.1 |
| Mozilla | Firefox | 19.0.2 |
| Mozilla | Firefox | 20.0 |
| Mozilla | Firefox | 20.0.1 |
| Mozilla | Firefox | 21.0 |
| Mozilla | Firefox | 22.0 |
| Mozilla | Firefox | 23.0 |
| Mozilla | Firefox | 23.0.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-5598?
How severe is CVE-2013-5598?
How do I fix CVE-2013-5598?
Are you affected by CVE-2013-5598?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
