Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to capture keystrokes entered on a web page, even when JavaScript is disabled, by using SVG animation accessKey events within that web page.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.mandriva.com/security/advisories?name=MDVSA-2011:192 | vendor advisory |
http://secunia.com/advisories/47334 | third party advisory vendor advisory |
http://www.securitytracker.com/id?1026447 | vdb entry |
http://www.securitytracker.com/id?1026446 | vdb entry |
https://bugzilla.mozilla.org/show_bug.cgi?id=704482 | |
http://secunia.com/advisories/49055 | third party advisory |
http://www.securitytracker.com/id?1026445 | vdb entry |
http://www.mozilla.org/security/announce/2011/mfsa2011-56.html | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/71911 | vdb entry |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14739 | vdb entry signature |
http://secunia.com/advisories/47302 | third party advisory vendor advisory |
http://osvdb.org/77954 | vdb entry |
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00009.html | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00001.html | vendor advisory |