CVE-2013-5598: Mozilla Firefox
High severity, CVSS 8.3. EPSS: 2.9% chance of exploitation in the next 30 days.
PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.
Affected products
- Mozilla Firefox: version 24.0 only; version 24.0.1 only; version 24.0.2 only; up to and including 24.0; version 19.0 only; version 19.0.1 only; …
Published 2013-10-30. Last modified 2026-06-16.