CVE-2013-1709

Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly handle the interaction between FRAME elements and history, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving spoofing a relative location in a previously visited document.

Published: 2013-08-06 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2013-1709 is rated Moderate Risk (41.7/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.34%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2013-1709

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.52% 1.34% +0.83%
2 2025-03-30 0.75% 0.52% -0.23%
3 2025-03-29 0.75%

Full EPSS history (6 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2013-1709

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
8.6 2.9 [email protected]

Weakness enumeration for CVE-2013-1709

OS Trackers for CVE-2013-1709

vendor priority summary link
gentoo high CVE-2013-1709: 1 GLSA(s) (201309-23), 6 atom(s) (mail-client/thunderbird, mail-client/thunderbird-bin, www-client/firefox, www-client/firefox-bin, www-client/seamonkey, www-client/seamonkey-bin); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2013-1709
redhat medium https://access.redhat.com/security/cve/CVE-2013-1709
suse medium CVE-2013-1709 severity moderate: SUSE including 82 source package names (MozillaFirefox-140.2.0-160000.1.2, MozillaFirefox-17.0.8esr-0.4.2.1, …), 112 product×package rows across 38 product lines (SUSE Linux Enterprise Desktop 11 SP2, SUSE Linux Enterprise Desktop 11 SP3, … (38 product lines)): Fixed 112. https://www.suse.com/security/cve/CVE-2013-1709/
ubuntu medium CVE-2013-1709 medium priority: Ubuntu including 2 source packages (firefox, thunderbird), 10 status rows across 5 suites (lucid, precise, quantal, raring, upstream): released 8, ignored 2. https://ubuntu.com/security/CVE-2013-1709

Affected software / configurations for CVE-2013-1709

Vendor Product Version Raw CPE
mozilla firefox 17.0 cpe:2.3:a:mozilla:firefox:17.0:*:*:*:*:*:*:*
mozilla firefox 17.0.1 cpe:2.3:a:mozilla:firefox:17.0.1:*:*:*:*:*:*:*
mozilla firefox 17.0.2 cpe:2.3:a:mozilla:firefox:17.0.2:*:*:*:*:*:*:*
mozilla firefox 17.0.3 cpe:2.3:a:mozilla:firefox:17.0.3:*:*:*:*:*:*:*
mozilla firefox 17.0.4 cpe:2.3:a:mozilla:firefox:17.0.4:*:*:*:*:*:*:*
mozilla firefox 17.0.5 cpe:2.3:a:mozilla:firefox:17.0.5:*:*:*:*:*:*:*
mozilla firefox 17.0.6 cpe:2.3:a:mozilla:firefox:17.0.6:*:*:*:*:*:*:*
mozilla firefox 17.0.7 cpe:2.3:a:mozilla:firefox:17.0.7:*:*:*:*:*:*:*
mozilla firefox <= 22.0 cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozilla firefox 19.0 cpe:2.3:a:mozilla:firefox:19.0:*:*:*:*:*:*:*
mozilla firefox 19.0.1 cpe:2.3:a:mozilla:firefox:19.0.1:*:*:*:*:*:*:*
mozilla firefox 19.0.2 cpe:2.3:a:mozilla:firefox:19.0.2:*:*:*:*:*:*:*
mozilla firefox 20.0 cpe:2.3:a:mozilla:firefox:20.0:*:*:*:*:*:*:*
mozilla firefox 20.0.1 cpe:2.3:a:mozilla:firefox:20.0.1:*:*:*:*:*:*:*
mozilla firefox 21.0 cpe:2.3:a:mozilla:firefox:21.0:*:*:*:*:*:*:*
mozilla thunderbird <= 17.0.7 cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
mozilla thunderbird 17.0 cpe:2.3:a:mozilla:thunderbird:17.0:*:*:*:*:*:*:*
mozilla thunderbird 17.0.1 cpe:2.3:a:mozilla:thunderbird:17.0.1:*:*:*:*:*:*:*
mozilla thunderbird 17.0.2 cpe:2.3:a:mozilla:thunderbird:17.0.2:*:*:*:*:*:*:*
mozilla thunderbird 17.0.3 cpe:2.3:a:mozilla:thunderbird:17.0.3:*:*:*:*:*:*:*
mozilla thunderbird 17.0.4 cpe:2.3:a:mozilla:thunderbird:17.0.4:*:*:*:*:*:*:*
mozilla thunderbird 17.0.5 cpe:2.3:a:mozilla:thunderbird:17.0.5:*:*:*:*:*:*:*
mozilla thunderbird 17.0.6 cpe:2.3:a:mozilla:thunderbird:17.0.6:*:*:*:*:*:*:*
mozilla thunderbird_esr 17.0 cpe:2.3:a:mozilla:thunderbird_esr:17.0:*:*:*:*:*:*:*
mozilla thunderbird_esr 17.0.1 cpe:2.3:a:mozilla:thunderbird_esr:17.0.1:*:*:*:*:*:*:*
mozilla thunderbird_esr 17.0.2 cpe:2.3:a:mozilla:thunderbird_esr:17.0.2:*:*:*:*:*:*:*
mozilla thunderbird_esr 17.0.3 cpe:2.3:a:mozilla:thunderbird_esr:17.0.3:*:*:*:*:*:*:*
mozilla thunderbird_esr 17.0.4 cpe:2.3:a:mozilla:thunderbird_esr:17.0.4:*:*:*:*:*:*:*
mozilla thunderbird_esr 17.0.5 cpe:2.3:a:mozilla:thunderbird_esr:17.0.5:*:*:*:*:*:*:*
mozilla thunderbird_esr 17.0.6 cpe:2.3:a:mozilla:thunderbird_esr:17.0.6:*:*:*:*:*:*:*
mozilla thunderbird_esr 17.0.7 cpe:2.3:a:mozilla:thunderbird_esr:17.0.7:*:*:*:*:*:*:*
mozilla seamonkey <= 2.20 cpe:2.3:a:mozilla:seamonkey:*:beta3:*:*:*:*:*:*
mozilla seamonkey 2.0 cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:*
mozilla seamonkey 2.0 cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1:*:*:*:*:*:*
mozilla seamonkey 2.0 cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2:*:*:*:*:*:*
mozilla seamonkey 2.0 cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3:*:*:*:*:*:*
mozilla seamonkey 2.0 cpe:2.3:a:mozilla:seamonkey:2.0:beta_1:*:*:*:*:*:*
mozilla seamonkey 2.0 cpe:2.3:a:mozilla:seamonkey:2.0:beta_2:*:*:*:*:*:*
mozilla seamonkey 2.0 cpe:2.3:a:mozilla:seamonkey:2.0:rc1:*:*:*:*:*:*
mozilla seamonkey 2.0 cpe:2.3:a:mozilla:seamonkey:2.0:rc2:*:*:*:*:*:*
mozilla seamonkey 2.0.1 cpe:2.3:a:mozilla:seamonkey:2.0.1:*:*:*:*:*:*:*
mozilla seamonkey 2.0.2 cpe:2.3:a:mozilla:seamonkey:2.0.2:*:*:*:*:*:*:*
mozilla seamonkey 2.0.3 cpe:2.3:a:mozilla:seamonkey:2.0.3:*:*:*:*:*:*:*
mozilla seamonkey 2.0.4 cpe:2.3:a:mozilla:seamonkey:2.0.4:*:*:*:*:*:*:*
mozilla seamonkey 2.0.5 cpe:2.3:a:mozilla:seamonkey:2.0.5:*:*:*:*:*:*:*
mozilla seamonkey 2.0.6 cpe:2.3:a:mozilla:seamonkey:2.0.6:*:*:*:*:*:*:*
mozilla seamonkey 2.0.7 cpe:2.3:a:mozilla:seamonkey:2.0.7:*:*:*:*:*:*:*
mozilla seamonkey 2.0.8 cpe:2.3:a:mozilla:seamonkey:2.0.8:*:*:*:*:*:*:*
mozilla seamonkey 2.0.9 cpe:2.3:a:mozilla:seamonkey:2.0.9:*:*:*:*:*:*:*
mozilla seamonkey 2.0.10 cpe:2.3:a:mozilla:seamonkey:2.0.10:*:*:*:*:*:*:*
mozilla seamonkey 2.0.11 cpe:2.3:a:mozilla:seamonkey:2.0.11:*:*:*:*:*:*:*
mozilla seamonkey 2.0.12 cpe:2.3:a:mozilla:seamonkey:2.0.12:*:*:*:*:*:*:*
mozilla seamonkey 2.0.13 cpe:2.3:a:mozilla:seamonkey:2.0.13:*:*:*:*:*:*:*
mozilla seamonkey 2.0.14 cpe:2.3:a:mozilla:seamonkey:2.0.14:*:*:*:*:*:*:*
mozilla seamonkey 2.1 cpe:2.3:a:mozilla:seamonkey:2.1:*:*:*:*:*:*:*
mozilla seamonkey 2.1 cpe:2.3:a:mozilla:seamonkey:2.1:alpha1:*:*:*:*:*:*
mozilla seamonkey 2.1 cpe:2.3:a:mozilla:seamonkey:2.1:alpha2:*:*:*:*:*:*
mozilla seamonkey 2.1 cpe:2.3:a:mozilla:seamonkey:2.1:alpha3:*:*:*:*:*:*
mozilla seamonkey 2.1 cpe:2.3:a:mozilla:seamonkey:2.1:beta1:*:*:*:*:*:*
mozilla seamonkey 2.1 cpe:2.3:a:mozilla:seamonkey:2.1:beta2:*:*:*:*:*:*
mozilla seamonkey 2.1 cpe:2.3:a:mozilla:seamonkey:2.1:beta3:*:*:*:*:*:*
mozilla seamonkey 2.1 cpe:2.3:a:mozilla:seamonkey:2.1:rc1:*:*:*:*:*:*
mozilla seamonkey 2.1 cpe:2.3:a:mozilla:seamonkey:2.1:rc2:*:*:*:*:*:*
mozilla seamonkey 2.2 cpe:2.3:a:mozilla:seamonkey:2.2:*:*:*:*:*:*:*
mozilla seamonkey 2.2 cpe:2.3:a:mozilla:seamonkey:2.2:beta1:*:*:*:*:*:*
mozilla seamonkey 2.2 cpe:2.3:a:mozilla:seamonkey:2.2:beta2:*:*:*:*:*:*
mozilla seamonkey 2.2 cpe:2.3:a:mozilla:seamonkey:2.2:beta3:*:*:*:*:*:*
mozilla seamonkey 2.3 cpe:2.3:a:mozilla:seamonkey:2.3:*:*:*:*:*:*:*
mozilla seamonkey 2.3 cpe:2.3:a:mozilla:seamonkey:2.3:beta1:*:*:*:*:*:*
mozilla seamonkey 2.3 cpe:2.3:a:mozilla:seamonkey:2.3:beta2:*:*:*:*:*:*
mozilla seamonkey 2.3 cpe:2.3:a:mozilla:seamonkey:2.3:beta3:*:*:*:*:*:*
mozilla seamonkey 2.3.1 cpe:2.3:a:mozilla:seamonkey:2.3.1:*:*:*:*:*:*:*
mozilla seamonkey 2.3.2 cpe:2.3:a:mozilla:seamonkey:2.3.2:*:*:*:*:*:*:*
mozilla seamonkey 2.3.3 cpe:2.3:a:mozilla:seamonkey:2.3.3:*:*:*:*:*:*:*
mozilla seamonkey 2.4 cpe:2.3:a:mozilla:seamonkey:2.4:*:*:*:*:*:*:*
mozilla seamonkey 2.4 cpe:2.3:a:mozilla:seamonkey:2.4:beta1:*:*:*:*:*:*
mozilla seamonkey 2.4 cpe:2.3:a:mozilla:seamonkey:2.4:beta2:*:*:*:*:*:*
mozilla seamonkey 2.4 cpe:2.3:a:mozilla:seamonkey:2.4:beta3:*:*:*:*:*:*
mozilla seamonkey 2.4.1 cpe:2.3:a:mozilla:seamonkey:2.4.1:*:*:*:*:*:*:*
mozilla seamonkey 2.5 cpe:2.3:a:mozilla:seamonkey:2.5:*:*:*:*:*:*:*

References for CVE-2013-1709

cvelogic Threat Intelligence