CVE-2013-5614
Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended sandbox restrictions via a crafted web site.
Date published : 2013-12-11
http://www.mozilla.org/security/announce/2013/mfsa2013-107.html
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html