CVE-2011-3866
N/A
N/A
Summary
Mozilla Firefox before 7.0 and SeaMonkey before 2.4 do not properly restrict availability of motion data events, which makes it easier for remote attackers to read keystrokes by leveraging JavaScript code running in a background tab.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.mozilla.org/security/announce/2011/mfsa2011-45.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13954
- https://bugzilla.mozilla.org/show_bug.cgi?id=682562
- http://www.usenix.org/events/hotsec11/tech/tech.html#Cai
References
- http://www.mozilla.org/security/announce/2011/mfsa2011-45.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13954
- https://bugzilla.mozilla.org/show_bug.cgi?id=682562
- http://www.usenix.org/events/hotsec11/tech/tech.html#Cai
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.