VDB
CVE-2005-2266
CVE-2005-2266
PUBLISHED
Reported by redhat · Published July 13, 2005
Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | *, n/a, n/a |
Timeline
- Jul 13, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 15549 third-party-advisoryx_refsource_SECUNIA
- DSA-810 vendor-advisoryx_refsource_DEBIAN
- SUSE-SR:2005:018 vendor-advisoryx_refsource_SUSE
- 15553 third-party-advisoryx_refsource_SECUNIA
- FLSA:160202 vendor-advisoryx_refsource_FEDORA
- 19823 third-party-advisoryx_refsource_SECUNIA
- RHSA-2005:587 vendor-advisoryx_refsource_REDHAT
- ADV-2005-1075 vdb-entryx_refsource_VUPEN
- RHSA-2005:601 vendor-advisoryx_refsource_REDHAT
- 15551 third-party-advisoryx_refsource_SECUNIA
- oval:org.mitre.oval:def:100107 vdb-entrysignaturex_refsource_OVAL
- oval:org.mitre.oval:def:1415 vdb-entrysignaturex_refsource_OVAL
- SUSE-SA:2005:045 vendor-advisoryx_refsource_SUSE
- 14242 vdb-entryx_refsource_BID
- RHSA-2005:586 vendor-advisoryx_refsource_REDHAT
- x_refsource_CONFIRM
- oval:org.mitre.oval:def:10712 vdb-entrysignaturex_refsource_OVAL
- SUSE-SA:2006:022 vendor-advisoryx_refsource_SUSE
- oval:org.mitre.oval:def:773 vdb-entrysignaturex_refsource_OVAL
- mozilla-frame-topfocus-xss(21332) vdb-entryx_refsource_XF