The child frames in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 inherit the default charset from the parent window, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1336-1 | New mozilla-firefox packages fix several vulnerabilities |
EUVD |
EUVD-2007-0990 | The child frames in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 inherit the default charset from the parent window, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set. |
Ubuntu USN |
USN-428-1 | Firefox vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T12:43:21.663Z
Reserved: 2007-02-16T00:00:00
Link: CVE-2007-0996
No data.
Status : Deferred
Published: 2007-02-27T02:28:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-0996
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN