{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-16T00:30:29.010","vulnerabilities":[{"cve":{"id":"CVE-2013-6853","sourceIdentifier":"cve@mitre.org","published":"2014-01-26T01:55:09.267","lastModified":"2025-04-11T00:51:21.963","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in clickstream.js in Y! Toolbar plugin for FireFox 3.1.0.20130813024103 for Mac, and 2.5.9.2013418100420 for Windows, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that is stored by the victim."},{"lang":"es","value":"Vulnerabilidad cross-site scripting (XSS) en clickstream.js de Y! Toolbar plugin para FireFox 3.1.0.20130813024103 para Mac, y 2.5.9.2013418100420 para Windows, permite a atacantes remotos inyectar script web o HTML de forma arbirtaria a través de una URL manipulada que es guardada por la victima."}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:yahoo:toolbar:3.1.0.20130813024103:*:*:*:*:*:*:*","matchCriteriaId":"60640F32-1D15-4C81-BC10-BDFBD12BCD77"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","matchCriteriaId":"14E6A30E-7577-4569-9309-53A0AF7FE3AC"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*","matchCriteriaId":"4C56F007-5F8E-4BDD-A803-C907BCC0AF55"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:yahoo:toolbar:2.5.9.2013418100420:*:*:*:*:*:*:*","matchCriteriaId":"A4EF0CDE-577C-494F-A2F8-D86FCB748A7F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","matchCriteriaId":"14E6A30E-7577-4569-9309-53A0AF7FE3AC"},{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*","matchCriteriaId":"4C56F007-5F8E-4BDD-A803-C907BCC0AF55"}]}]}],"references":[{"url":"http://osvdb.org/102175","source":"cve@mitre.org"},{"url":"http://packetstormsecurity.com/files/124800/Y-Toolbar-Cross-Site-Scripting.html","source":"cve@mitre.org"},{"url":"http://www.cloudscan.me/2014/01/cve-2013-6853-stored-xss-in-y-toolbar.html","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/64971","source":"cve@mitre.org"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/90529","source":"cve@mitre.org"},{"url":"http://osvdb.org/102175","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://packetstormsecurity.com/files/124800/Y-Toolbar-Cross-Site-Scripting.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.cloudscan.me/2014/01/cve-2013-6853-stored-xss-in-y-toolbar.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/64971","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/90529","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}