The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade netscape7Upgrade kdebaseUpgrade firefoxUpgrade mozillaUpgrade linux-mozillaUpgrade mozilla-gtk1Upgrade linux-mozilla-develUpgrade kdelibsUpgrade linux-operaUpgrade opera | Dec 10, 2025 | Aug 12, 2004 |
| Suse | — | Upgrade mozilla-calendarUpgrade mozillaUpgrade mozilla-venkmanUpgrade mozilla-dom-inspectorUpgrade mozilla-mailUpgrade mozilla-irc | Feb 17, 2015 | Jul 27, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub