Firefox prior to 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote malicious users to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mozilla firefox 0.10.1 |
||
mozilla firefox 0.8 |
||
mozilla firefox 0.9.2 |
||
mozilla firefox 0.9.3 |
||
mozilla firefox 0.10 |
||
mozilla firefox 0.9 |
||
mozilla firefox 1.0 |
||
mozilla firefox 0.9.1 |