Open Vulnerability and Assessment Language (OVAL)
Contact Us Downloads News September 4, 2008 Search
link to OVAL home page

View Definition

Definition Id: oval:org.mitre.oval:def:100053 Date: 2007-04-23
Title: Mozilla Inactive Tab Form Data Theft Vulnerability
Description: Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers to steal sensitive data that is intended for other sites, which could facilitate phishing attacks.
Version: 5 Class: vulnerability
Status: ACCEPTED Reference(s): CVE-2004-1381
Family: windows
Platform(s): Microsoft Windows NT
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Product(s): mozilla
Firefox
Definition Synopsis:

OVAL is CVE Compatible