Lucene search

K
cvelistMitreCVELIST:CVE-2010-0170
HistoryMar 25, 2010 - 8:31 p.m.

CVE-2010-0170

2010-03-2520:31:00
mitre
www.cve.org
7

AI Score

8.5

Confidence

High

EPSS

0.003

Percentile

68.2%

Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected window.location protection mechanism, which might allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors that are specific to each affected plugin.

AI Score

8.5

Confidence

High

EPSS

0.003

Percentile

68.2%