Security readout for executives and security teams
This flaw affects old Mozilla mail clients and browser-suite software. A malicious email could abuse an IFRAME with a data URL to inject script or HTML, but the attack requires user interaction. Business risk is mainly legacy desktop exposure, not modern server-side compromise. Exposure is likely limited to environments still running the named legacy Thunderbird, Thunderbird ESR, or SeaMonkey versions. Organizations using managed modern mail clients or updated Mozilla packages are unlikely to be affected, based on the provided version ranges. Prioritize if legacy Mozilla mail clients remain in use, especially on high-value user workstations. If the environment has retired or updated these products, urgency is low to moderate and should be handled through legacy software cleanup. Mitigation focus: Identify any Thunderbird 17.x, Thunderbird ESR 17.x, or SeaMonkey before 2.20 installations.; Update affected Mozilla products using Mozilla or operating-system vendor advisories.; Consult MFSA2014-14 and Ubuntu USN-2119-1 for package-specific remediation details..
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2013-6674 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://bugzilla.mozilla.org/show_bug.cgi?id=868267CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
