Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to reference remote files and possibly load chrome: URLs by tricking the user into copying or dragging links.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.134
EPSS Ranking 93.9%