Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2013-09-18T10:00:00

Updated: 2024-08-06T15:13:32.377Z

Reserved: 2013-02-13T00:00:00

Link: CVE-2013-1737

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2013-09-18T10:08:24.740

Modified: 2017-09-19T01:36:14.123

Link: CVE-2013-1737

cve-icon Redhat

Severity : Moderate

Publid Date: 2013-09-17T00:00:00Z

Links: CVE-2013-1737 - Bugzilla