Mozilla Firefox before 7.0 and SeaMonkey before 2.4 do not properly restrict availability of motion data events, which makes it easier for remote attackers to read keystrokes by leveraging JavaScript code running in a background tab.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.mozilla.org/security/announce/2011/mfsa2011-45.html | vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13954 | vdb entry third party advisory signature |
https://bugzilla.mozilla.org/show_bug.cgi?id=682562 | issue tracking vendor advisory |
http://www.usenix.org/events/hotsec11/tech/tech.html#Cai | third party advisory |