Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files.
| Software | From | Fixed in |
|---|---|---|
| mozilla / thunderbird | - | 0.7.x |
| mozilla / firefox | - | 0.9.x |
| mozilla / mozilla | - | 1.7.x |