← Back

CVE-2014-1561

nvd nist
Published: Jul 23, 2014Modified: May 6, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:P
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

Mozilla Firefox before 31.0 does not properly restrict use of drag-and-drop events to spoof customization events, which allows remote attackers to alter the placement of UI icons via crafted JavaScript code that is encountered during (1) page, (2) panel, or (3) toolbar customization.

Affected (2)

Products: Mozilla: Firefox · Oracle: Solaris
1 product
Firefox
1 product
Solaris
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 30.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.3

Related CWEs

References (16)

Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Source: security@mozilla.org
Issue Tracking
Source: security@mozilla.org
Issue Tracking
Source: security@mozilla.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.