Unrated severityNVD Advisory· Published Sep 18, 2013· Updated Jun 16, 2026
CVE-2013-1727
CVE-2013-1727
Description
Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks or obtain password or cookie information, by using a symlink in conjunction with a file: URL for a local file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <=23.0.1
- cpe:2.3:a:mozilla:firefox:19.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:19.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:19.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:20.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:20.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:21.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:22.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:23.0:*:*:*:*:*:*:*
- (no CPE)range: <24.0
Patches
Vulnerability mechanics
References
5- www.mozilla.org/security/announce/2013/mfsa2013-84.htmlnvdVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2013-September/115907.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2013-September/116610.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2013-September/117526.htmlnvd
- bugzilla.mozilla.org/show_bug.cginvd
News mentions
0No linked articles in our index yet.