cbcvebase.
CVE-2013-5593
published 2013-10-30

CVE-2013-5593: The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not…

PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.99%
78.4th percentile
The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly restrict the nature or placement of HTML within a dropdown menu, which allows remote attackers to spoof the address bar or conduct clickjacking attacks via vectors that trigger navigation off of a page containing this element.

Affected

64 ranges· showing 25
VendorProductVersion rangeFixed in
mozillafirefox<= 24.0
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillaseamonkey<= 2.22
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey
mozillaseamonkey

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu5.0MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.