Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade ja-linux-mozillafirebird-gtk1Upgrade linux-firefoxUpgrade ru-linux-mozillafirebirdUpgrade de-netscape7Upgrade mozilla+ipv6Upgrade linux-mozilla-develUpgrade netscape7Upgrade zhTW-linux-mozillafirebirdUpgrade linux-mozillaUpgrade linux-phoenixUpgrade linux-netscapeUpgrade el-linux-mozillafirebirdUpgrade de-linux-netscapeUpgrade linux-mozillafirebirdUpgrade mozilla-gtk2Upgrade zhCN-linux-mozillafirebirdUpgrade fr-linux-netscapeUpgrade ja-mozillafirebird-gtk2Upgrade ja-netscape7Upgrade mozilla-gtk1Upgrade ja-linux-netscapeUpgrade mozilla-embeddedUpgrade de-linux-mozillafirebirdUpgrade phoenixUpgrade mozilla-gtkUpgrade pt_BR-netscape7Upgrade firefoxUpgrade mozilla-firebirdUpgrade mozillaUpgrade mozilla-thunderbirdUpgrade fr-netscape7 | Dec 10, 2025 | Jul 16, 2005 |
| Ubuntu | — | Upgrade mozilla-firefox-locale-nbUpgrade mozilla-firefox-locale-trUpgrade mozilla-firefox-locale-ukUpgrade mozilla-firefox-locale-jaUpgrade mozilla-browserUpgrade mozilla-firefox | Nov 8, 2024 | Jul 13, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub