CVE-2013-5614 PUBLISHED

Reported by mozilla · Published December 11, 2013

Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended sandbox restrictions via a crafted web site.

Affected Products

VendorProductVersions
n/an/an/a
n/an/an/a

Timeline

References

Open in Interactive Console →