Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.2.1.2011.56
Category:General
Title:Mozilla Firefox Security Advisory (MFSA2011-56) - Linux
Summary:This host is missing a security update for Mozilla Firefox.
Description:Summary:
This host is missing a security update for Mozilla Firefox.

Vulnerability Insight:
Key detection without JavaScript via SVG animation

Security researcher Mario Heiderich reported it was
possible to use SVG animation accessKey events to detect
key strokes even when JavaScript was disabled. Since web pages can normally
detect key events through script and most users have scripting enabled this
does not present a risk for most users. In contexts where the user knows
scripting is disabled (reading mail, for example, or NoScript users) this
could allow a malicious web page to fool a user into interacting with
a prompt thinking it came from the browser or mail program.

Affected Software/OS:
Firefox version(s) below 9.

Solution:
The vendor has released an update. Please see the reference(s) for more information.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-3663
http://www.mandriva.com/security/advisories?name=MDVSA-2011:192
http://osvdb.org/77954
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14739
http://www.securitytracker.com/id?1026445
http://www.securitytracker.com/id?1026446
http://www.securitytracker.com/id?1026447
http://secunia.com/advisories/47302
http://secunia.com/advisories/47334
http://secunia.com/advisories/49055
SuSE Security Announcement: openSUSE-SU-2012:0007 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00001.html
SuSE Security Announcement: openSUSE-SU-2012:0039 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00009.html
XForce ISS Database: firefox-svg-animation-info-disc(71911)
https://exchange.xforce.ibmcloud.com/vulnerabilities/71911
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.