Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2005-2267 | Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents. |
Ubuntu USN |
USN-149-1 | Firefox vulnerabilities |
Ubuntu USN |
USN-149-3 | Ubuntu 4.10 update for Firefox vulnerabilities |
Ubuntu USN |
USN-155-1 | Mozilla vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T22:22:48.659Z
Reserved: 2005-07-13T00:00:00
Link: CVE-2005-2266
No data.
Status : Deferred
Published: 2005-07-13T04:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2005-2266
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN