CVE-2011-0067Improper Input Validation in Mozilla Firefox

Severity
5.0MEDIUMNVD
EPSS
0.5%
top 33.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 7
Latest updateMay 17

Description

Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly implement autocompletion for forms, which allows remote attackers to read form history entries via a Java applet that spoofs interaction with the autocomplete controls.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDmozilla/firefox3.5.18+102
NVDmozilla/seamonkey2.0.13+46

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pjfj-jcfm-mvm5: Mozilla Firefox before 32022-05-17
CVEList
CVE-2011-0067: Mozilla Firefox before 32011-05-07

📋Vendor Advisories

6
Ubuntu
Thunderbird regression2011-06-06
Ubuntu
Thunderbird vulnerabilities2011-05-05
Ubuntu
Thunderbird vulnerabilities2011-05-05
Ubuntu
Xulrunner vulnerabilities2011-04-30
Ubuntu
Firefox and Xulrunner vulnerabilities2011-04-29

💬Community

1
Bugzilla
CVE-2011-0067 Mozilla untrusted events can trigger autocomplete popup (MFSA 2011-14)2011-04-28
CVE-2011-0067 — Improper Input Validation in Mozilla | cvebase