Firefox 1.0 allows remote attackers to execute arbitrary code via plugins that load "privileged content" into frames, as demonstrated using certain XUL events when a user drags a scrollbar two times, aka "Firescrolling."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.047
EPSS Ranking 89.4%