CVE-2013-0794: Mozilla Firefox

Medium severity, CVSS 5.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Mozilla Firefox before 20.0 and SeaMonkey before 2.17 do not prevent origin spoofing of tab-modal dialogs, which allows remote attackers to conduct phishing attacks via a crafted web site.

Affected products

  • Mozilla Firefox: up to and including 19.0.2; version 19.0 only; version 19.0.1 only
  • Mozilla Seamonkey: up to and including 2.17; version 2.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; …

Published 2013-04-03. Last modified 2026-06-16.