CVE-2015-0810: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 1.5% chance of exploitation in the next 30 days.

Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote attackers to conduct clickjacking attacks via a Flash object in conjunction with DIV elements associated with layered presentation, and crafted JavaScript code that interacts with an IMG element.

Affected products

  • Mozilla Firefox: up to and including 36.0.4

Published 2015-04-01. Last modified 2026-06-17.