Mozilla Firefox and Thunderbird before 1.5.0.4 associates XUL attributes with the wrong URL under certain unspecified circumstances, which might allow remote attackers to bypass restrictions by causing a persisted string to be associated with the wrong URL.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.079
EPSS Ranking 91.7%