CVE-2010-0178: Code Injection
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mouse clicks as drag-and-drop actions, which allows remote attackers to execute arbitrary JavaScript with Chrome privileges by loading a chrome: URL and then loading a javascript: URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0178?
CVE-2010-0178 is classified as a moderate severity vulnerability.
How do I fix CVE-2010-0178?
To fix CVE-2010-0178, users should upgrade to Firefox version 3.0.19, 3.5.9, or 3.6.2, or later versions.
What are the potential impacts of CVE-2010-0178?
CVE-2010-0178 allows attackers to execute arbitrary JavaScript with Chrome privileges through a malicious applet.
Which versions of Firefox are affected by CVE-2010-0178?
CVE-2010-0178 affects Firefox versions before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2.
What other software besides Firefox is impacted by CVE-2010-0178?
CVE-2010-0178 also affects SeaMonkey versions before 2.0.4.