Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 do not prevent multiple wrapping of WebIDL objects, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17097
http://www.ubuntu.com/usn/USN-1729-2
http://www.ubuntu.com/usn/USN-1729-1
http://www.mozilla.org/security/announce/2013/mfsa2013-23.html
http://lists.opensuse.org/opensuse-updates/2013-02/msg00062.html
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.html