CVE-2011-3866

Description

Mozilla Firefox before 7.0 and SeaMonkey before 2.4 do not properly restrict availability of motion data events, which makes it easier for remote attackers to read keystrokes by leveraging JavaScript code running in a background tab.

Risk Information

Base Score
4.3
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.418

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Mozilla Firefox (x64) 6.0Windows
Multiple vulnerabilities affected in Mozilla_Firefox 6.0Windows
Multiple vulnerabilities affected in SeaMonkey 2.3.3Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 7.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 7.0Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-343016Mozilla Firefox (x64) (132.0.2)
PATCH-343015Mozilla Firefox (132.0.2)
PATCH-341197SeaMonkey (2.53.19)
PATCH-334458Mozilla Firefox (x64) (120.0)
PATCH-334457Mozilla Firefox (120.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234