CVE-2009-0253
Mozilla Firefox <3.0.5 - XSS
Title source: llmDescription
Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Status Bar Obfuscation" and "Clickjacking" attack.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by MrDoug · htmlremotewindows
https://www.exploit-db.com/exploits/7842
Scores
EPSS
0.0387
EPSS Percentile
88.3%
Details
Status
published
Products (1)
mozilla/firefox
3.0.5
Published
Jan 22, 2009
Tracked Since
Feb 18, 2026