Mozilla Firefox before 31.0 does not properly restrict use of drag-and-drop events to spoof customization events, which allows remote attackers to alter the placement of UI icons via crafted JavaScript code that is encountered during (1) page, (2) panel, or (3) toolbar customization.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefoxUpgrade thunderbirdUpgrade nssUpgrade firefox-esrUpgrade linux-firefoxUpgrade linux-thunderbird | Dec 10, 2025 | Jul 23, 2014 |
| Gentoo Linux | — | Upgrade www-client/firefox.Upgrade dev-libs/nspr.Upgrade www-client/firefox-bin.Upgrade www-client/seamonkey.Upgrade www-client/seamonkey-bin.Upgrade mail-client/thunderbird.Upgrade mail-client/thunderbird-bin. | Oct 30, 2017 | Jul 23, 2014 |
| Mfsa2014 60 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 31.0 | Jul 28, 2014 | Jul 23, 2014 |
| Oracle Solaris | — | Upgrade runtime/tcl-8/tcl-sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade web/browser/firefox to version 38.4.0-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3/documentation to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3 | May 29, 2017 | Jul 23, 2014 |
| Suse | — | Upgrade MozillaFirefox-develUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-translations-common | Dec 18, 2015 | Jul 23, 2014 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Jul 23, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub