CVE-2013-1711: Mozilla Firefox
Medium severity, CVSS 4.3. EPSS: 2.2% chance of exploitation in the next 30 days.
The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging access to an unprivileged object.
Affected products
- Mozilla Firefox: up to and including 22.0; version 19.0 only; version 19.0.1 only; version 19.0.2 only; version 20.0 only; version 20.0.1 only; …
- Mozilla Seamonkey: up to and including 2.20; version 2.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; …
Published 2013-08-07. Last modified 2026-06-16.