Back

HIGH

: seamonkey cookie setting / same-domain bypass vulnerability

Published Feb 16, 2007

Description

Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (61)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 16, 2007
Updated Aug 7, 2024
Reserved Feb 15, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Feb 23, 2007