CVE
- Id
- 13472
- CVE No.
- CVE-2005-2266
- Status
- Candidate
- Description
- Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.
- Phase
- Assigned (20050713)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
97487 | 13472 | CVE-2005-2266 | CONFIRM:http://www.mozilla.org/security/announce/mfsa2005-52.html | View |
97488 | 13472 | CVE-2005-2266 | DEBIAN:DSA-810 | View |
97489 | 13472 | CVE-2005-2266 | URL:http://www.debian.org/security/2005/dsa-810 | View |
97490 | 13472 | CVE-2005-2266 | FEDORA:FLSA:160202 | View |
97491 | 13472 | CVE-2005-2266 | URL:https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202 | View |
97492 | 13472 | CVE-2005-2266 | REDHAT:RHSA-2005:586 | View |
97493 | 13472 | CVE-2005-2266 | URL:http://www.redhat.com/support/errata/RHSA-2005-586.html | View |
97494 | 13472 | CVE-2005-2266 | REDHAT:RHSA-2005:587 | View |
97495 | 13472 | CVE-2005-2266 | URL:http://www.redhat.com/support/errata/RHSA-2005-587.html | View |
97496 | 13472 | CVE-2005-2266 | REDHAT:RHSA-2005:601 | View |
97497 | 13472 | CVE-2005-2266 | URL:http://www.redhat.com/support/errata/RHSA-2005-601.html | View |
97498 | 13472 | CVE-2005-2266 | SUSE:SUSE-SA:2006:022 | View |
97499 | 13472 | CVE-2005-2266 | URL:http://www.novell.com/linux/security/advisories/2006_04_25.html | View |
97500 | 13472 | CVE-2005-2266 | SUSE:SUSE-SA:2005:045 | View |
97501 | 13472 | CVE-2005-2266 | URL:http://www.novell.com/linux/security/advisories/2005_45_mozilla.html | View |
97502 | 13472 | CVE-2005-2266 | SUSE:SUSE-SR:2005:018 | View |
97503 | 13472 | CVE-2005-2266 | URL:http://www.novell.com/linux/security/advisories/2005_18_sr.html | View |
97504 | 13472 | CVE-2005-2266 | BID:14242 | View |
97505 | 13472 | CVE-2005-2266 | URL:http://www.securityfocus.com/bid/14242 | View |
97506 | 13472 | CVE-2005-2266 | OVAL:oval:org.mitre.oval:def:10712 | View |
97507 | 13472 | CVE-2005-2266 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10712 | View |
97508 | 13472 | CVE-2005-2266 | VUPEN:ADV-2005-1075 | View |
97509 | 13472 | CVE-2005-2266 | URL:http://www.vupen.com/english/advisories/2005/1075 | View |
97510 | 13472 | CVE-2005-2266 | OVAL:oval:org.mitre.oval:def:100107 | View |
97511 | 13472 | CVE-2005-2266 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100107 | View |
97512 | 13472 | CVE-2005-2266 | OVAL:oval:org.mitre.oval:def:1415 | View |
97513 | 13472 | CVE-2005-2266 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1415 | View |
97514 | 13472 | CVE-2005-2266 | OVAL:oval:org.mitre.oval:def:773 | View |
97515 | 13472 | CVE-2005-2266 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:773 | View |
97516 | 13472 | CVE-2005-2266 | SECUNIA:15549 | View |
97517 | 13472 | CVE-2005-2266 | URL:http://secunia.com/advisories/15549 | View |
97518 | 13472 | CVE-2005-2266 | SECUNIA:15551 | View |
97519 | 13472 | CVE-2005-2266 | URL:http://secunia.com/advisories/15551 | View |
97520 | 13472 | CVE-2005-2266 | SECUNIA:15553 | View |
97521 | 13472 | CVE-2005-2266 | URL:http://secunia.com/advisories/15553 | View |
97522 | 13472 | CVE-2005-2266 | SECUNIA:19823 | View |
97523 | 13472 | CVE-2005-2266 | URL:http://secunia.com/advisories/19823 | View |
97524 | 13472 | CVE-2005-2266 | XF:mozilla-frame-topfocus-xss(21332) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
62197 | JVNDB-2005-000399 | 複数の Web ブラウザにおける JavaScript にダイアログボックスのなりすましの脆弱性 | Microsoft Internet Explorer、 Mozilla Firefox、 Mozilla には、JavaScript によるダイアログボックスに発行元 URL を表示しないため、信頼できる Web サイトより開かれたダイアログボックスになりすますことが可能である脆弱性が存在します。 | CVE-2005-2268 | 13472 | 2.6 | http://jvndb.jvn.jp/ja/contents/2005/JVNDB-2005-000399.html | View |