CVE-2007-3511
published 2007-07-03CVE-2007-3511: The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.36%
81.8th percentile
The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| mozilla | firefox | <= 2.0.0.7 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 1.1.4 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2007-10-23·CVSS 4.0
CVE-2006-2894 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Various flaws were discovered in the layout and JavaScript engines. By
tricking a user into opening a malicious web page, an attacker could
execute arbitrary code with the user's privileges. (CVE-2007-5339,
CVE-2007-5340)
Flaws were discovered in the file upload form control. By tricking
a user into opening a malicious web page, an attacker could force
arbitrary files from the user's computer to be uploaded without their
consent. (CVE-2006-2894, CVE-2007-3511)
Michal Zalewski discovered that the onUnload event handlers were
incorrectly able to access information outside the old page content. A
malicious web site could exploit this to modify the contents, or
steal confidential data (such as passwords), of the next l
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2007-10-22·CVSS 4.0
CVE-2007-5334 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Various flaws were discovered in the layout and JavaScript engines.
By tricking a user into opening a malicious web page, an attacker could
execute arbitrary code with the user's privileges. (CVE-2007-5336,
CVE-2007-5339, CVE-2007-5340)
Michal Zalewski discovered that the onUnload event handlers were
incorrectly able to access information outside the old page content.
A malicious web site could exploit this to modify the contents, or steal
confidential data (such as passwords), of the next loaded web page.
(CVE-2007-1095)
Stefano Di Paola discovered that Firefox did not correctly request
Digest Authentications. A malicious web site could exploit this to
inject arbitrary HTTP headers or perform session splitting attacks
aga
Red Hat
security flaw
vendor_redhat·2007-06-30·CVSS 4.3
CVE-2007-3511 [MEDIUM] security flaw
security flaw
The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.
GHSA
GHSA-9mmm-2pp6-2xv5: The focus handling for the onkeydown event in Microsoft Internet Explorer 6
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2007-5158 [MEDIUM] GHSA-9mmm-2pp6-2xv5: The focus handling for the onkeydown event in Microsoft Internet Explorer 6
The focus handling for the onkeydown event in Microsoft Internet Explorer 6.0 allows remote attackers to change field focus and copy keystrokes via a certain use of a JavaScript htmlFor attribute, as demonstrated by changing focus from a textarea to a file upload field, a related issue to CVE-2007-3511.
GHSA
GHSA-vqj2-jf89-h87v: The focus handling for the onkeydown event in Mozilla Firefox 1
ghsa_unreviewed·2022-05-01
CVE-2007-3511 [MEDIUM] GHSA-vqj2-jf89-h87v: The focus handling for the onkeydown event in Mozilla Firefox 1
The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-3511 security flaw
bugzilla·2018-08-16·CVSS 4.3
CVE-2007-3511 [MEDIUM] CVE-2007-3511 security flaw
CVE-2007-3511 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.
Bugzilla
Mozilla products security update (CVE-2007-1095, CVE-2007-2292, CVE-2007-3511, CVE-2007-3844, CVE-2007-5334, CVE-2007-5337, CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)
bugzilla·2007-10-16·CVSS 6.8
CVE-2007-1095 [MEDIUM] Mozilla products security update (CVE-2007-1095, CVE-2007-2292, CVE-2007-3511, CVE-2007-3844, CVE-2007-5334, CVE-2007-5337, CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)
Mozilla products security update (CVE-2007-1095, CVE-2007-2292, CVE-2007-3511, CVE-2007-3844, CVE-2007-5334, CVE-2007-5337, CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)
Here is a rough breakdown of the flaws grouped by type. The official
definition of these issues can be found on the upstream security page here:
http://www.mozilla.org/projects/security/known-vulnerabilities.html
Leveraging browser flaws, fooling users into possibly surrendering sensitive
information (Moderate):
CVE-2007-1095, CVE-2007-3511, CVE-2007-3844, CVE-2007-5334
Malformed web content could result in the execution of arbitrary commands
(Critical):
CVE-2007-5336, CVE-2007-5338, CVE-2007-5339, CVE-2007-5340
Digest Authentication requests can be used to conduct a response splitting
attack (Moderate):
CVE-2007-2292
http://archives.neohapsis.com/archives/fulldisclosure/2007-06/0646.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2007-06/0658.htmlhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://osvdb.org/37994http://secunia.com/advisories/25904http://secunia.com/advisories/27276http://secunia.com/advisories/27298http://secunia.com/advisories/27325http://secunia.com/advisories/27327http://secunia.com/advisories/27335http://secunia.com/advisories/27336http://secunia.com/advisories/27356http://secunia.com/advisories/27383http://secunia.com/advisories/27387http://secunia.com/advisories/27403http://secunia.com/advisories/27414http://secunia.com/advisories/27425http://secunia.com/advisories/27480http://secunia.com/advisories/27680http://securitytracker.com/id?1018837http://sla.ckers.org/forum/read.php?3%2C13142http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1http://support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.htmlhttp://www.debian.org/security/2007/dsa-1392http://www.debian.org/security/2007/dsa-1396http://www.debian.org/security/2007/dsa-1401http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:202http://www.mozilla.org/security/announce/2007/mfsa2007-32.htmlhttp://www.novell.com/linux/security/advisories/2007_57_mozilla.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0979.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0980.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0981.htmlhttp://www.securityfocus.com/archive/1/482876/100/200/threadedhttp://www.securityfocus.com/archive/1/482925/100/0/threadedhttp://www.securityfocus.com/archive/1/482932/100/200/threadedhttp://www.securityfocus.com/bid/24725http://www.ubuntu.com/usn/usn-536-1http://www.vupen.com/english/advisories/2007/3544http://www.vupen.com/english/advisories/2007/3587http://www.vupen.com/english/advisories/2008/0083http://yathong.googlepages.com/FirefoxFocusBug.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/35299https://issues.rpath.com/browse/RPL-1858https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9763https://usn.ubuntu.com/535-1/https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00498.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-October/msg00285.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-October/msg00355.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2007-06/0646.htmlhttp://archives.neohapsis.com/archives/fulldisclosure/2007-06/0658.htmlhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://osvdb.org/37994http://secunia.com/advisories/25904http://secunia.com/advisories/27276http://secunia.com/advisories/27298http://secunia.com/advisories/27325http://secunia.com/advisories/27327http://secunia.com/advisories/27335http://secunia.com/advisories/27336http://secunia.com/advisories/27356http://secunia.com/advisories/27383http://secunia.com/advisories/27387http://secunia.com/advisories/27403http://secunia.com/advisories/27414http://secunia.com/advisories/27425http://secunia.com/advisories/27480http://secunia.com/advisories/27680http://securitytracker.com/id?1018837http://sla.ckers.org/forum/read.php?3%2C13142http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1http://support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.htmlhttp://www.debian.org/security/2007/dsa-1392http://www.debian.org/security/2007/dsa-1396http://www.debian.org/security/2007/dsa-1401http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:202http://www.mozilla.org/security/announce/2007/mfsa2007-32.htmlhttp://www.novell.com/linux/security/advisories/2007_57_mozilla.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0979.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0980.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0981.htmlhttp://www.securityfocus.com/archive/1/482876/100/200/threadedhttp://www.securityfocus.com/archive/1/482925/100/0/threadedhttp://www.securityfocus.com/archive/1/482932/100/200/threadedhttp://www.securityfocus.com/bid/24725http://www.ubuntu.com/usn/usn-536-1http://www.vupen.com/english/advisories/2007/3544http://www.vupen.com/english/advisories/2007/3587http://www.vupen.com/english/advisories/2008/0083http://yathong.googlepages.com/FirefoxFocusBug.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/35299https://issues.rpath.com/browse/RPL-1858https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9763https://usn.ubuntu.com/535-1/https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00498.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-October/msg00285.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-October/msg00355.html
2007-07-03
Published