CVE-2009-0253

Mozilla Firefox <3.0.5 - XSS

Title source: llm

Description

Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Status Bar Obfuscation" and "Clickjacking" attack.

Exploits (1)

exploitdb WORKING POC VERIFIED
by MrDoug · htmlremotewindows
https://www.exploit-db.com/exploits/7842

Scores

EPSS 0.0387
EPSS Percentile 88.3%

Details

Status published
Products (1)
mozilla/firefox 3.0.5
Published Jan 22, 2009
Tracked Since Feb 18, 2026