CVE Vulnerabilities

CVE-2011-3866

Published: Sep 29, 2011 | Modified: Nov 29, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Mozilla Firefox before 7.0 and SeaMonkey before 2.4 do not properly restrict availability of motion data events, which makes it easier for remote attackers to read keystrokes by leveraging JavaScript code running in a background tab.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 7.0 (including)
Firefox Ubuntu hardy *
Firefox Ubuntu natty *
Seamonkey Ubuntu hardy *
Seamonkey Ubuntu lucid *
Seamonkey Ubuntu maverick *
Seamonkey Ubuntu natty *
Seamonkey Ubuntu oneiric *

References