CVE-2011-3663Sensitive Information Exposure in Mozilla Seamonkey

Severity
4.3MEDIUMNVD
EPSS
1.0%
top 23.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 21
Latest updateMay 17

Description

Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to capture keystrokes entered on a web page, even when JavaScript is disabled, by using SVG animation accessKey events within that web page.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/seamonkey2.5+57
NVDmozilla/firefox9 versions+8
NVDmozilla/thunderbird6 versions+5

🔴Vulnerability Details

2
GHSA
GHSA-556m-v442-wjx4: Mozilla Firefox 42022-05-17
CVEList
CVE-2011-3663: Mozilla Firefox 42011-12-21

📋Vendor Advisories

4
Ubuntu
Thunderbird vulnerabilities2012-01-24
Ubuntu
Mozvoikko and ubufox update2012-01-06
Ubuntu
Firefox vulnerabilities2012-01-06
Red Hat
Mozilla: Multiple security flaws fixed in v3.6.25 (Mac) and v92011-12-20
CVE-2011-3663 — Sensitive Information Exposure | cvebase