Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-5598

Опубликовано: 30 окт. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 8.3

Описание

PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.

РелизСтатусПримечание
devel

released

25.0+build3-0ubuntu0.13.10.1
lucid

ignored

end of life
precise

released

25.0+build3-0ubuntu0.12.04.1
quantal

released

25.0+build3-0ubuntu0.12.10.1
raring

released

25.0+build3-0ubuntu0.13.04.1
saucy

released

25.0+build3-0ubuntu0.13.10.1
upstream

released

25.0

Показывать по

EPSS

Процентиль: 73%
0.00781
Низкий

8.3 High

CVSS2

Связанные уязвимости

redhat
больше 12 лет назад

PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.

nvd
больше 12 лет назад

PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.

debian
больше 12 лет назад

PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 ...

github
больше 3 лет назад

PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.

EPSS

Процентиль: 73%
0.00781
Низкий

8.3 High

CVSS2