Back

MEDIUM

Mozilla: Sandbox restrictions not applied to nested object elements (MFSA 2013-107)

Published Dec 11, 2013

Description

Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended sandbox restrictions via a crafted web site.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Dec 11, 2013
Updated Aug 6, 2024
Reserved Aug 26, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Dec 10, 2013