CVE-2005-2266

Firefox < 1.0.5 and Mozilla < 1.7.9 - Same Origin Policy Bypass via Child Frame Method Calls

Title source: llm
STIX 2.1

Description

Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.

References (20)

Core 20
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2005/dsa-810
Issue Tracking vendor-advisory x_refsource_fedora
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100107
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-587.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/15549
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2005_18_sr.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/15553
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19823
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/1075
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-601.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/15551
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1415
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2005_45_mozilla.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14242
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-586.html
Patch, Vendor Advisory x_refsource_confirm
http://www.mozilla.org/security/announce/mfsa2005-52.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10712
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_04_25.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A773
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/21332

Scores

EPSS 0.0183
EPSS Percentile 76.5%

Details

Status published
Products (26)
mozilla/firefox 0.8
mozilla/firefox 0.9 (2 CPE variants)
mozilla/firefox 0.9.1
mozilla/firefox 0.9.2
mozilla/firefox 0.9.3
mozilla/firefox 0.10
mozilla/firefox 0.10.1
mozilla/firefox 1.0
mozilla/firefox 1.0.1
mozilla/firefox 1.0.2
... and 16 more
Published Jul 13, 2005
Tracked Since Feb 18, 2026