CVE-2013-1670 describes a vulnerability in the Chrome Object Wrapper (COW) implementation within Mozilla Firefox and Thunderbird, including their ESR versions, that allows remote attackers to bypass read-only restrictions and perform cross-site scripting (XSS) attacks. This medium-severity vulnerability (CVSS 4.3) has a network attack vector and low impact on integrity, with no impact on confidentiality or availability. While not listed in CISA's KEV catalog, exploit code for this specific vulnerability is available in ExploitDB, and it has garnered significant community discussion and media coverage, indicating a notable level of attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
19.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:19.0:*:*:*:*:*:*:* | ||
19.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:19.0.1:*:*:*:*:*:*:* | ||
19.0.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:19.0.2:*:*:*:*:*:*:* | ||
20.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:20.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.