CVE-2010-0170
Mozilla Firefox - XSS
Title source: ruleDescription
Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected window.location protection mechanism, which might allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors that are specific to each affected plugin.
References (7)
Scores
EPSS
0.0050
EPSS Percentile
65.6%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
mozilla/firefox
n/a/n/a
Timeline
Published
Mar 25, 2010
Tracked Since
Feb 18, 2026