Oval Definition:oval:org.mitre.oval:def:24799
Revision Date:2014-10-06Version:17
Title:Mozilla Firefox before 31.0 does not properly restrict use of drag-and-drop events to spoof customization events, which allows remote attackers to alter the placement of UI icons via crafted JavaScript code that is encountered during (1) page, (2) panel, or (3) toolbar customization.
Description:Mozilla Firefox before 31.0 does not properly restrict use of drag-and-drop events to spoof customization events, which allows remote attackers to alter the placement of UI icons via crafted JavaScript code that is encountered during (1) page, (2) panel, or (3) toolbar customization.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2014-1561
Platform(s):Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Mozilla Firefox
Definition Synopsis
  • Mozilla Firefox Mainline release is installed
  • AND Mozilla Firefox Mainline version less than 31.0
  • BACK