The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers use of a user-defined (1) toString or (2) valueOf method.
Conclusion & alert: CVE-2013-1697 is rated High Risk (68/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 3.18%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 2.64% | 3.18% | +0.54% |
| 2 | 2025-12-28 | 1.91% | 2.64% | +0.73% |
| 3 | 2025-07-09 | — | 1.91% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.3 | 2.0 | HIGH |
|
8.6 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
gentoo
|
high | CVE-2013-1697: 1 GLSA(s) (201309-23), 6 atom(s) (mail-client/thunderbird, mail-client/thunderbird-bin, www-client/firefox, www-client/firefox-bin, www-client/seamonkey, www-client/seamonkey-bin); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2013-1697 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2013-1697 |
suse
|
critical | CVE-2013-1697 severity critical: SUSE including 69 source package names (MozillaFirefox-140.2.0-160000.1.2, MozillaFirefox-17.0.7esr-0.3.1, …), 106 product×package rows across 38 product lines (SUSE Linux Enterprise Desktop 11 SP2, SUSE Linux Enterprise Desktop 11 SP3, … (38 product lines)): Fixed 106. | https://www.suse.com/security/cve/CVE-2013-1697/ |
ubuntu
|
medium | CVE-2013-1697 medium priority: Ubuntu including 4 source packages (firefox, seamonkey, thunderbird, xulrunner-1.9.2), 20 status rows across 5 suites (lucid, precise, quantal, raring, upstream): released 8, DNE 6, ignored 4, needs-triage 2. | https://ubuntu.com/security/CVE-2013-1697 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| mozilla | firefox | <= 21.0 | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
| mozilla | firefox | 19.0 | cpe:2.3:a:mozilla:firefox:19.0:*:*:*:*:*:*:* |
| mozilla | firefox | 19.0.1 | cpe:2.3:a:mozilla:firefox:19.0.1:*:*:*:*:*:*:* |
| mozilla | firefox | 19.0.2 | cpe:2.3:a:mozilla:firefox:19.0.2:*:*:*:*:*:*:* |
| mozilla | firefox | 20.0 | cpe:2.3:a:mozilla:firefox:20.0:*:*:*:*:*:*:* |
| mozilla | firefox | 20.0.1 | cpe:2.3:a:mozilla:firefox:20.0.1:*:*:*:*:*:*:* |
| mozilla | firefox | 17.0 | cpe:2.3:a:mozilla:firefox:17.0:*:*:*:*:*:*:* |
| mozilla | firefox | 17.0.1 | cpe:2.3:a:mozilla:firefox:17.0.1:*:*:*:*:*:*:* |
| mozilla | firefox | 17.0.2 | cpe:2.3:a:mozilla:firefox:17.0.2:*:*:*:*:*:*:* |
| mozilla | firefox | 17.0.3 | cpe:2.3:a:mozilla:firefox:17.0.3:*:*:*:*:*:*:* |
| mozilla | firefox | 17.0.4 | cpe:2.3:a:mozilla:firefox:17.0.4:*:*:*:*:*:*:* |
| mozilla | firefox | 17.0.5 | cpe:2.3:a:mozilla:firefox:17.0.5:*:*:*:*:*:*:* |
| mozilla | firefox | 17.0.6 | cpe:2.3:a:mozilla:firefox:17.0.6:*:*:*:*:*:*:* |
| mozilla | thunderbird | <= 17.0.6 | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
| mozilla | thunderbird | 17.0 | cpe:2.3:a:mozilla:thunderbird:17.0:*:*:*:*:*:*:* |
| mozilla | thunderbird | 17.0.1 | cpe:2.3:a:mozilla:thunderbird:17.0.1:*:*:*:*:*:*:* |
| mozilla | thunderbird | 17.0.2 | cpe:2.3:a:mozilla:thunderbird:17.0.2:*:*:*:*:*:*:* |
| mozilla | thunderbird | 17.0.3 | cpe:2.3:a:mozilla:thunderbird:17.0.3:*:*:*:*:*:*:* |
| mozilla | thunderbird | 17.0.4 | cpe:2.3:a:mozilla:thunderbird:17.0.4:*:*:*:*:*:*:* |
| mozilla | thunderbird | 17.0.5 | cpe:2.3:a:mozilla:thunderbird:17.0.5:*:*:*:*:*:*:* |
| mozilla | thunderbird_esr | 17.0 | cpe:2.3:a:mozilla:thunderbird_esr:17.0:*:*:*:*:*:*:* |
| mozilla | thunderbird_esr | 17.0.1 | cpe:2.3:a:mozilla:thunderbird_esr:17.0.1:*:*:*:*:*:*:* |
| mozilla | thunderbird_esr | 17.0.2 | cpe:2.3:a:mozilla:thunderbird_esr:17.0.2:*:*:*:*:*:*:* |
| mozilla | thunderbird_esr | 17.0.3 | cpe:2.3:a:mozilla:thunderbird_esr:17.0.3:*:*:*:*:*:*:* |
| mozilla | thunderbird_esr | 17.0.4 | cpe:2.3:a:mozilla:thunderbird_esr:17.0.4:*:*:*:*:*:*:* |
| mozilla | thunderbird_esr | 17.0.5 | cpe:2.3:a:mozilla:thunderbird_esr:17.0.5:*:*:*:*:*:*:* |
| mozilla | thunderbird_esr | 17.0.6 | cpe:2.3:a:mozilla:thunderbird_esr:17.0.6:*:*:*:*:*:*:* |