CVE-2011-3663
published 2011-12-21CVE-2011-3663: Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to capture keystrokes entered on a web page, even…
PriorityP414medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.08%
79.6th percentile
Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to capture keystrokes entered on a web page, even when JavaScript is disabled, by using SVG animation accessKey events within that web page.
Affected
73 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 2.5 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_ubuntu7.5HIGH
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2012-01-24·CVSS 7.5
CVE-2011-3658 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Alexandre Poirot, Chris Blizzard, Kyle Huey, Scoobidiver, Christian Holler,
David Baron, Gary Kwong, Jim Blandy, Bob Clary, Jesse Ruderman, Marcia
Knous, and Rober Longson discovered several memory safety issues which
could possibly be exploited to crash Thunderbird or execute arbitrary code
as the user that invoked Thunderbird. (CVE-2011-3660)
Aki Helin discovered a crash in the YARR regular expression library that
could be triggered by javascript in web content. (CVE-2011-3661)
It was discovered that a flaw in the Mozilla SVG implementation could
result in an out-of-bounds memory access if SVG elements were removed
during a DOMAttrModified event handler. An attacker could potentially
exploi
Ubuntu
Mozvoikko and ubufox update
vendor_ubuntu·2012-01-06·CVSS 7.5
[HIGH] Mozvoikko and ubufox update
Title: Mozvoikko and ubufox update
Summary: This update provides compatible packages for Firefox 9.
USN-1306-1 fixed vulnerabilities in Firefox. This update provides updated
Mozvoikko and ubufox packages for use with Firefox 9.
Original advisory details:
Alexandre Poirot, Chris Blizzard, Kyle Huey, Scoobidiver, Christian Holler,
David Baron, Gary Kwong, Jim Blandy, Bob Clary, Jesse Ruderman, Marcia
Knous, and Rober Longson discovered several memory safety issues which
could possibly be exploited to crash Firefox or execute arbitrary code as
the user that invoked Firefox. (CVE-2011-3660)
Aki Helin discovered a crash in the YARR regular expression library that
could be triggered by javascript in web content. (CVE-2011-3661)
It was discovered that a flaw in the Mozilla SVG implementatio
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2012-01-06·CVSS 7.5
CVE-2011-3660 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Alexandre Poirot, Chris Blizzard, Kyle Huey, Scoobidiver, Christian Holler,
David Baron, Gary Kwong, Jim Blandy, Bob Clary, Jesse Ruderman, Marcia
Knous, and Rober Longson discovered several memory safety issues which
could possibly be exploited to crash Firefox or execute arbitrary code as
the user that invoked Firefox. (CVE-2011-3660)
Aki Helin discovered a crash in the YARR regular expression library that
could be triggered by javascript in web content. (CVE-2011-3661)
It was discovered that a flaw in the Mozilla SVG implementation could
result in an out-of-bounds memory access if SVG elements were removed
during a DOMAttrModified event handler. An attacker could potentially
exploit this vulnerabi
Red Hat
Mozilla: Multiple security flaws fixed in v3.6.25 (Mac) and v9
vendor_redhat·2011-12-20·CVSS 4.3
CVE-2011-3663 [MEDIUM] Mozilla: Multiple security flaws fixed in v3.6.25 (Mac) and v9
Mozilla: Multiple security flaws fixed in v3.6.25 (Mac) and v9
Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to capture keystrokes entered on a web page, even when JavaScript is disabled, by using SVG animation accessKey events within that web page.
Statement: This issue did not affect the version of firefox and thunderbird packages as shipped with Red Hat Enterprise Linux 4, 5 and 6. This issue did not affect the version of seamonkey package as shipped with Red Hat Enterprise Linux 4.
GHSA
GHSA-556m-v442-wjx4: Mozilla Firefox 4
ghsa_unreviewed·2022-05-17
CVE-2011-3663 [MEDIUM] CWE-200 GHSA-556m-v442-wjx4: Mozilla Firefox 4
Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to capture keystrokes entered on a web page, even when JavaScript is disabled, by using SVG animation accessKey events within that web page.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-01/msg00009.htmlhttp://osvdb.org/77954http://secunia.com/advisories/47302http://secunia.com/advisories/47334http://secunia.com/advisories/49055http://www.mandriva.com/security/advisories?name=MDVSA-2011:192http://www.mozilla.org/security/announce/2011/mfsa2011-56.htmlhttp://www.securitytracker.com/id?1026445http://www.securitytracker.com/id?1026446http://www.securitytracker.com/id?1026447https://bugzilla.mozilla.org/show_bug.cgi?id=704482https://exchange.xforce.ibmcloud.com/vulnerabilities/71911https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14739http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-01/msg00009.htmlhttp://osvdb.org/77954http://secunia.com/advisories/47302http://secunia.com/advisories/47334http://secunia.com/advisories/49055http://www.mandriva.com/security/advisories?name=MDVSA-2011:192http://www.mozilla.org/security/announce/2011/mfsa2011-56.htmlhttp://www.securitytracker.com/id?1026445http://www.securitytracker.com/id?1026446http://www.securitytracker.com/id?1026447https://bugzilla.mozilla.org/show_bug.cgi?id=704482https://exchange.xforce.ibmcloud.com/vulnerabilities/71911https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14739
2011-12-21
Published