Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote attackers to conduct clickjacking attacks via a Flash object in conjunction with DIV elements associated with layered presentation, and crafted JavaScript code that interacts with an IMG element.
CVSS Details
- CVSS 3.1 Base Score: 5.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade seamonkeyUpgrade firefox-esrUpgrade linux-seamonkeyUpgrade thunderbirdUpgrade linux-firefoxUpgrade firefoxUpgrade linux-thunderbirdUpgrade libxul | Dec 10, 2025 | Mar 31, 2015 |
| Gentoo Linux | — | Upgrade www-client/firefox.Upgrade mail-client/thunderbird.Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird-bin. | Oct 30, 2017 | Apr 1, 2015 |
| Mfsa2015 35 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 37.0 | Apr 2, 2015 | Apr 1, 2015 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.35.0 | Oct 22, 2015 | Apr 1, 2015 |
| Oracle Solaris | — | Upgrade database/sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3/documentation to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade web/browser/firefox to version 38.4.0-0.175.3.8.0.2.0 on Solaris 11.3Upgrade runtime/tcl-8/tcl-sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3 | May 29, 2017 | Apr 1, 2015 |
| Suse | — | Upgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox | Dec 9, 2016 | Apr 1, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub