CVE-2013-1710 describes a critical vulnerability in Mozilla Firefox, Thunderbird, and SeaMonkey versions prior to their respective updates. This flaw, residing in the crypto.generateCRMFRequest function, allows remote attackers to execute arbitrary JavaScript or conduct cross-site scripting (XSS) attacks during Certificate Request Message Format (CRMF) generation. With a CVSS score of 10.0, it represents a severe risk, enabling unauthenticated attackers to achieve complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, exploit modules are publicly available in Metasploit and ExploitDB, and it has garnered significant community discussion and media coverage, indicating its historical relevance and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.20CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:*:beta3:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.