Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript code to read and write to the clipboard, and possibly obtain sensitive information, via script-generated events such as Ctrl-Ins.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/11179 | exploit vdb entry patch |
http://www.kb.cert.org/vuls/id/460528 | third party advisory us government resource |
http://www.novell.com/linux/security/advisories/2004_36_mozilla.html | patch vendor advisory |
http://marc.info/?l=bugtraq&m=109900315219363&w=2 | vendor advisory |
http://bugzilla.mozilla.org/show_bug.cgi?id=257523 | patch exploit |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9745 | vdb entry signature |
http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3 | |
http://security.gentoo.org/glsa/glsa-200409-26.xml | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17376 | vdb entry |
http://marc.info/?l=bugtraq&m=109698896104418&w=2 | vendor advisory |
http://secunia.com/advisories/12526 | third party advisory |