CVE-2005-2266
Firefox < 1.0.5 and Mozilla < 1.7.9 - Same Origin Policy Bypass via Child Frame Method Calls
Title source: llmDescription
Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.
References (20)
Core 20
Core References
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2005/dsa-810
Issue Tracking vendor-advisory
x_refsource_fedora
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100107
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-587.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/15549
Vendor Advisory vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2005_18_sr.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/15553
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/19823
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2005/1075
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-601.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/15551
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1415
Vendor Advisory vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2005_45_mozilla.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/14242
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-586.html
Patch, Vendor Advisory x_refsource_confirm
http://www.mozilla.org/security/announce/mfsa2005-52.html
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10712
Vendor Advisory vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_04_25.html
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A773
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/21332
Scores
EPSS
0.0183
EPSS Percentile
76.5%
Details
Status
published
Products (26)
mozilla/firefox
0.8
mozilla/firefox
0.9 (2 CPE variants)
mozilla/firefox
0.9.1
mozilla/firefox
0.9.2
mozilla/firefox
0.9.3
mozilla/firefox
0.10
mozilla/firefox
0.10.1
mozilla/firefox
1.0
mozilla/firefox
1.0.1
mozilla/firefox
1.0.2
... and 16 more
Published
Jul 13, 2005
Tracked Since
Feb 18, 2026