4.3
CVSSv2

CVE-2015-0810

Published: 01/04/2015 Updated: 07/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Mozilla Firefox prior to 37.0 on OS X does not ensure that the cursor is visible, which allows remote malicious users to conduct clickjacking attacks via a Flash object in conjunction with DIV elements associated with layered presentation, and crafted JavaScript code that interacts with an IMG element.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Mozilla Foundation Security Advisory 2015-35 Cursor clickjacking with flash and images Announced March 31, 2015 Reporter Jordi Chancel Impact Moderate Products Firefox, SeaMonkey Fixed in ...