CVE-2011-3866 Information

Description

Mozilla Firefox before 7.0 and SeaMonkey before 2.4 do not properly restrict availability of motion data events which makes it easier for remote attackers to read keystrokes by leveraging JavaScript code running in a background tab.

Reference

http://www.mozilla.org/security/announce/2011/mfsa2011-45.html http://www.usenix.org/events/hotsec11/tech/tech.htmlCai https://bugzilla.mozilla.org/show_bug.cgi?id=682562 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A13954

Share on: