Lucene search

K
cve[email protected]CVE-2002-2013
HistoryOct 03, 2022 - 4:23 p.m.

CVE-2002-2013

2022-10-0316:23:50
web.nvd.nist.gov
19
cve-2002-2013
nvd
information security
remote attack
cookie theft
mozilla
netscape

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

62.2%

Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.

Affected configurations

NVD
Node
mozillamozillaMatch0.9.2
OR
mozillamozillaMatch0.9.2.1
OR
mozillamozillaMatch0.9.3
OR
mozillamozillaMatch0.9.4
OR
mozillamozillaMatch0.9.4.1
OR
mozillamozillaMatch0.9.5
OR
mozillamozillaMatch0.9.6
OR
netscapecommunicatorMatch4.0
OR
netscapecommunicatorMatch4.4
OR
netscapecommunicatorMatch4.5
OR
netscapecommunicatorMatch4.5_beta
OR
netscapecommunicatorMatch4.06
OR
netscapecommunicatorMatch4.6
OR
netscapecommunicatorMatch4.07
OR
netscapecommunicatorMatch4.7
OR
netscapecommunicatorMatch4.08
OR
netscapecommunicatorMatch4.51
OR
netscapecommunicatorMatch4.61
OR
netscapecommunicatorMatch4.72
OR
netscapecommunicatorMatch4.73
OR
netscapecommunicatorMatch4.74
OR
netscapecommunicatorMatch4.75
OR
netscapecommunicatorMatch4.76
OR
netscapecommunicatorMatch4.77
OR
netscapecommunicatorMatch4.78
OR
netscapenavigatorMatch4.77
OR
netscapenavigatorMatch6.0
OR
netscapenavigatorMatch6.01
OR
netscapenavigatorMatch6.1
OR
netscapenavigatorMatch6.2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

62.2%

Related for CVE-2002-2013