CVE-2010-2442

Microsoft Internet Explorer - Keystroke Exposure via Cross-Domain IFRAME Focus Manipulation

Title source: llm
STIX 2.1

Description

Microsoft Internet Explorer, possibly 8, does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets."

References (1)

Core 1
Core References
Issue Tracking x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=552255

Scores

EPSS 0.1161
EPSS Percentile 95.6%

Details

CWE
CWE-264
Status published
Products (1)
microsoft/internet_explorer
Published Jun 24, 2010
Tracked Since Feb 18, 2026