Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent the starting of a download in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | * | 3.6.22 (including) |
Firefox | Mozilla | 3.6 (including) | 3.6 (including) |
Firefox | Mozilla | 3.6.2 (including) | 3.6.2 (including) |
Firefox | Mozilla | 3.6.3 (including) | 3.6.3 (including) |
Firefox | Mozilla | 3.6.4 (including) | 3.6.4 (including) |
Firefox | Mozilla | 3.6.6 (including) | 3.6.6 (including) |
Firefox | Mozilla | 3.6.7 (including) | 3.6.7 (including) |
Firefox | Mozilla | 3.6.8 (including) | 3.6.8 (including) |
Firefox | Mozilla | 3.6.9 (including) | 3.6.9 (including) |
Firefox | Mozilla | 3.6.10 (including) | 3.6.10 (including) |
Firefox | Mozilla | 3.6.11 (including) | 3.6.11 (including) |
Firefox | Mozilla | 3.6.12 (including) | 3.6.12 (including) |
Firefox | Mozilla | 3.6.13 (including) | 3.6.13 (including) |
Firefox | Mozilla | 3.6.14 (including) | 3.6.14 (including) |
Firefox | Mozilla | 3.6.15 (including) | 3.6.15 (including) |
Firefox | Mozilla | 3.6.16 (including) | 3.6.16 (including) |
Firefox | Mozilla | 3.6.17 (including) | 3.6.17 (including) |
Firefox | Mozilla | 3.6.18 (including) | 3.6.18 (including) |
Firefox | Mozilla | 3.6.19 (including) | 3.6.19 (including) |
Firefox | Mozilla | 3.6.20 (including) | 3.6.20 (including) |
Firefox | Mozilla | 3.6.21 (including) | 3.6.21 (including) |