Security Advisory

CVE-2010-0178

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2010-04-05 17:00:00
Last updated 2024-08-07 00:37:54
Assigner mitre
State PUBLISHED

Description

Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mouse clicks as drag-and-drop actions, which allows remote attackers to execute arbitrary JavaScript with Chrome privileges by loading a chrome: URL and then loading a javascript: URL.