CVE-2010-0170

Mozilla Firefox - XSS

Title source: rule

Description

Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected window.location protection mechanism, which might allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors that are specific to each affected plugin.

Scores

EPSS 0.0050
EPSS Percentile 65.6%

Classification

CWE
CWE-79
Status published

Affected Products (2)

mozilla/firefox
n/a/n/a

Timeline

Published Mar 25, 2010
Tracked Since Feb 18, 2026