Vulnerability · NVD
CVE-2013-1710
The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allows remote attackers to execute arbitrary JavaScript code or conduct cross-site scripting (XSS) attacks via vectors related to Certificate Request Message Format (CRMF) request generation.
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
NVD references 4 distinct products for this CVE — only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗
Vulnerable CPE configurations (8)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| mozilla |
thunderbird All platforms (wildcard)
|
All platforms (wildcard) | ≤17.0.7 | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
| mozilla |
thunderbird All platforms (wildcard)
|
All platforms (wildcard) | — | cpe:2.3:a:mozilla:thunderbird:17.0:*:*:*:*:*:*:* |
| mozilla |
thunderbird All platforms (wildcard)
|
All platforms (wildcard) | — | cpe:2.3:a:mozilla:thunderbird:17.0.1:*:*:*:*:*:*:* |
| mozilla |
thunderbird All platforms (wildcard)
|
All platforms (wildcard) | — | cpe:2.3:a:mozilla:thunderbird:17.0.2:*:*:*:*:*:*:* |
| mozilla |
thunderbird All platforms (wildcard)
|
All platforms (wildcard) | — | cpe:2.3:a:mozilla:thunderbird:17.0.3:*:*:*:*:*:*:* |
| mozilla |
thunderbird All platforms (wildcard)
|
All platforms (wildcard) | — | cpe:2.3:a:mozilla:thunderbird:17.0.4:*:*:*:*:*:*:* |
| mozilla |
thunderbird All platforms (wildcard)
|
All platforms (wildcard) | — | cpe:2.3:a:mozilla:thunderbird:17.0.5:*:*:*:*:*:*:* |
| mozilla |
thunderbird All platforms (wildcard)
|
All platforms (wildcard) | — | cpe:2.3:a:mozilla:thunderbird:17.0.6:*:*:*:*:*:*:* |