Lucene search

K
ubuntucveUbuntu.comUB:CVE-2007-0981
HistoryFeb 16, 2007 - 12:00 a.m.

CVE-2007-0981

2007-02-1600:00:00
ubuntu.com
ubuntu.com
14

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.97

Percentile

99.8%

Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before
2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the
same origin policy, steal cookies, and conduct other attacks by writing a
URI with a null byte to the hostname (location.hostname) DOM property, due
to interactions with DNS resolver code.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchfirefox< 1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1UNKNOWN
ubuntu6.10noarchfirefox< 2.0.0.6+0dfsg-0ubuntu0.6.10UNKNOWN
ubuntu7.04noarchfirefox< 2.0.0.6+1-0ubuntu1UNKNOWN
ubuntu7.10noarchiceape< 1.1.4-1ubuntu2UNKNOWN
ubuntu7.10noarchlightning-sunbird< 0.5-0ubuntu4UNKNOWN
ubuntu7.10noarchmidbrowser< 0.1.6b-0ubuntu2UNKNOWN
ubuntu7.04noarchxulrunner< 1.8.0.10-3ubuntu1UNKNOWN
ubuntu7.10noarchxulrunner< 1.8.0.10-3ubuntu1UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.97

Percentile

99.8%