CVE-2013-0793: Mozilla Firefox
Medium severity, CVSS 4.3. EPSS: 2.2% chance of exploitation in the next 30 days.
Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 do not ensure the correctness of the address bar during history navigation, which allows remote attackers to conduct cross-site scripting (XSS) attacks or phishing attacks by leveraging control over navigation timing.
Affected products
- Mozilla Firefox: up to and including 19.0.2; version 19.0 only; version 19.0.1 only; version 17.0 only; version 17.0.1 only; version 17.0.2 only; …
- Mozilla Seamonkey: up to and including 2.17; version 2.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; …
- Mozilla Thunderbird: version 17.0 only; version 17.0.1 only; version 17.0.2 only; version 17.0.3 only; version 17.0.4 only
- Mozilla Thunderbird ESR: version 17.0 only; version 17.0.1 only; version 17.0.2 only; version 17.0.3 only; version 17.0.4 only
Published 2013-04-03. Last modified 2026-06-16.