CVE-2009-3370
29.10.2009, 14:30
Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverage the auto-fill feature to populate form fields, in an attacker-readable form, with history entries.Enginsight
| Vendor | Product | Version |
|---|---|---|
| mozilla | firefox | 3.0 |
| mozilla | firefox | 3.0:alpha |
| mozilla | firefox | 3.0:beta2 |
| mozilla | firefox | 3.0:beta5 |
| mozilla | firefox | 3.0.1 |
| mozilla | firefox | 3.0.2 |
| mozilla | firefox | 3.0.3 |
| mozilla | firefox | 3.0.4 |
| mozilla | firefox | 3.0.5 |
| mozilla | firefox | 3.0.6 |
| mozilla | firefox | 3.0.7 |
| mozilla | firefox | 3.0.8 |
| mozilla | firefox | 3.0.9 |
| mozilla | firefox | 3.0.10 |
| mozilla | firefox | 3.0.11 |
| mozilla | firefox | 3.0.12 |
| mozilla | firefox | 3.0.13 |
| mozilla | firefox | 3.0.14 |
| mozilla | firefox | 3.5.1 |
| mozilla | firefox | 3.5.2 |
| mozilla | firefox | 3.5.3 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| firefox-3.5 |
| ||||||||||
| xulrunner-1.9.1 |
|
References