CVE Reference: CVE-2004-0718

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-0718

Description:
The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/1598

SUSE
  http://www.novell.com/linux/security/advisories/2004_36_mozilla.html

SCO

SAID
  Secunia Advisory: SA11978

REDHAT
  http://www.redhat.com/support/errata/RHSA-2004-421.html

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4756
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9997

MISC
  http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/

MANDRAKE
  http://www.mandriva.com/security/advisories?name=MDKSA-2004:082

FEDORA
  http://marc.theaimsgroup.com/?l=bugtraq&m=109900315219363&w=2

DEBIAN
  http://www.debian.org/security/2005/dsa-810
  http://www.debian.org/security/2005/dsa-777

CONFIRM
  http://bugzilla.mozilla.org/show_bug.cgi?id=246448

BID
  15495


Return to the previous page.