Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ubuntu | — | Upgrade mozilla-firefox-locale-jaUpgrade mozilla-firefox-locale-ukUpgrade mozilla-firefox-locale-nbUpgrade mozilla-firefoxUpgrade mozilla-firefox-locale-tr | Nov 8, 2024 | Jan 24, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub