The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This vulnerability has a 3.26% probability of being exploited in the next 30 days, ranking higher than 88% of all scored CVEs.