Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly implement autocompletion for forms, which allows remote attackers to read form history entries via a Java applet that spoofs interaction with the autocomplete controls.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade xulrunnerUpgrade firefoxUpgrade xulrunner-devel | Dec 1, 2016 | May 7, 2011 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/thunderbird-bin.Upgrade net-libs/xulrunner-bin.Upgrade dev-libs/nss.Upgrade www-client/seamonkey.Upgrade mail-client/thunderbird.Upgrade net-libs/xulrunner.Upgrade www-client/firefox.Upgrade www-client/firefox-bin.Upgrade www-client/seamonkey-bin.Upgrade www-client/icecat.Upgrade www-client/mozilla-firefox. | Oct 30, 2017 | May 7, 2011 |
| Mfsa2011 14 | — | Upgrade to Mozilla Firefox version 3.6.17Upgrade to Mozilla Firefox version 3.5.19 | Jun 14, 2012 | May 7, 2011 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.0.14 | Feb 3, 2012 | May 7, 2011 |
| Oracle_linux | — | Upgrade xulrunnerUpgrade xulrunner-develUpgrade firefox | Oct 16, 2024 | May 7, 2011 |
| Suse | — | Upgrade mozilla-xulrunner192-x86Upgrade MozillaFirefox-develUpgrade mozilla-xulrunner192-gnomeUpgrade mozilla-xulrunner192-develUpgrade mozilla-xulrunner192-translations-32bitUpgrade mozilla-xulrunner192Upgrade mozilla-xulrunner192-translationsUpgrade mozilla-xulrunner192-gnome-32bitUpgrade MozillaFirefox-translationsUpgrade mozilla-xulrunner192-32bitUpgrade MozillaFirefox | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade thunderbirdUpgrade firefoxUpgrade xulrunner-1.9.1Upgrade xulrunner-1.9.2 | Nov 8, 2024 | May 7, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub