Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-3511

Опубликовано: 03 июл. 2007
Источник: ubuntu
Приоритет: low
CVSS2: 4.3

Описание

The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.

РелизСтатусПримечание
dapper

released

1.5.dfsg+1.5.0.14~prepatch071011b-0ubuntu1
devel

not-affected

edgy

released

2.0.0.8+0dfsg-0ubuntu0.6.10
feisty

released

2.0.0.8+1nobinonly-0ubuntu1
gutsy

released

2.0.0.8+2nobinonly-0ubuntu1
upstream

released

2.0.0.8

Показывать по

РелизСтатусПримечание
dapper

released

1.5.0.13+1.5.0.14b-0ubuntu0.6.06
edgy

released

1.5.0.13+1.5.0.14b-0ubuntu0.6.10
feisty

released

1.5.0.13+1.5.0.14b-0ubuntu0.7.04
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

gutsy

released

2.0.0.8~pre071022+nobinonly-0ubuntu0.7.10
upstream

released

2.0.0.8

Показывать по

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 18 лет назад

The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.

nvd
больше 18 лет назад

The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.

debian
больше 18 лет назад

The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12 ...

github
почти 4 года назад

The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.

oracle-oval
больше 18 лет назад

ELSA-2007-0979: Critical: firefox security update (CRITICAL)

4.3 Medium

CVSS2