Red Hat Bugzilla – Bug 608040
CVE-2010-2441 WebKit: Keystrokes sent to hidden frame rather than visible frame due to javascript flaw
Last modified: 2015-07-13 13:48:26 EDT
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2441 to the following vulnerability: WebKit does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets," a different vulnerability than CVE-2010-1126, CVE-2010-1422, and CVE-2010-2295. References: [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2441 [2] https://bugzilla.mozilla.org/show_bug.cgi?id=552255
Created attachment 426888 [details] Local copy of public PoC from Mozilla upstream bug [2]