CVE-2007-0981
Last modified
CVE-2007-0981 is a vulnerability of currently unknown severity. Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.. EPSS estimates a 12.14% chance of exploitation in the next 30 days.
Description
Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | <= 1.5.0.9 |
| Mozilla | Firefox | 0.8 |
| Mozilla | Firefox | 0.9 |
| Mozilla | Firefox | 0.9.1 |
| Mozilla | Firefox | 0.9.2 |
| Mozilla | Firefox | 0.9.3 |
| Mozilla | Firefox | 0.10 |
| Mozilla | Firefox | 0.10.1 |
| Mozilla | Firefox | 1.0 |
| Mozilla | Firefox | 1.0.1 |
| Mozilla | Firefox | 1.0.2 |
| Mozilla | Firefox | 1.0.3 |
| Mozilla | Firefox | 1.0.4 |
| Mozilla | Firefox | 1.0.5 |
| Mozilla | Firefox | 1.0.6 |
| Mozilla | Firefox | 1.0.7 |
| Mozilla | Firefox | 1.0.8 |
| Mozilla | Firefox | 1.5 |
| Mozilla | Firefox | 1.5.0.1 |
| Mozilla | Firefox | 1.5.0.2 |
| Mozilla | Firefox | 1.5.0.3 |
| Mozilla | Firefox | 1.5.0.4 |
| Mozilla | Firefox | 1.5.0.5 |
| Mozilla | Firefox | 1.5.0.6 |
| Mozilla | Firefox | 1.5.0.7 |
| Mozilla | Firefox | 1.5.0.8 |
| Mozilla | Firefox | 1.5.1 |
| Mozilla | Firefox | 1.5.2 |
| Mozilla | Firefox | 1.5.3 |
| Mozilla | Firefox | 1.5.4 |
| Mozilla | Firefox | 1.5.5 |
| Mozilla | Firefox | 1.5.6 |
| Mozilla | Firefox | 1.5.7 |
| Mozilla | Firefox | 1.5.8 |
| Mozilla | Firefox | 2.0 |
| Mozilla | Firefox | 2.0.0.1 |
| Mozilla | Firefox | preview_release |
| Mozilla | Seamonkey | <= 1.0.7 |
| Mozilla | Seamonkey | 1.0 |
| Mozilla | Seamonkey | 1.0.1 |
| Mozilla | Seamonkey | 1.0.2 |
| Mozilla | Seamonkey | 1.0.3 |
| Mozilla | Seamonkey | 1.0.4 |
| Mozilla | Seamonkey | 1.0.5 |
| Mozilla | Seamonkey | 1.0.6 |
References
- http://rhn.redhat.com/errata/RHSA-2007-0077.htmlVendor Advisory
- http://secunia.com/advisories/24175Vendor Advisory
- http://secunia.com/advisories/24205Vendor Advisory
- http://secunia.com/advisories/24238Vendor Advisory
- http://secunia.com/advisories/24287Vendor Advisory
- http://secunia.com/advisories/24290Vendor Advisory
- http://secunia.com/advisories/24293Vendor Advisory
- http://secunia.com/advisories/24320Vendor Advisory
- http://secunia.com/advisories/24328Vendor Advisory
- http://secunia.com/advisories/24333Vendor Advisory
- http://secunia.com/advisories/24342Vendor Advisory
- http://secunia.com/advisories/24343Vendor Advisory
- http://secunia.com/advisories/24384Vendor Advisory
- http://secunia.com/advisories/24393Vendor Advisory
- http://secunia.com/advisories/24395Vendor Advisory
- http://secunia.com/advisories/24437Vendor Advisory
- http://secunia.com/advisories/24455Vendor Advisory
- http://secunia.com/advisories/24457Vendor Advisory
- http://secunia.com/advisories/24650Vendor Advisory
- http://www.kb.cert.org/vuls/id/885753US Government Resource
- http://www.redhat.com/support/errata/RHSA-2007-0078.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0079.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0097.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0108.htmlVendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=370445Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2007-0077.htmlVendor Advisory
- http://secunia.com/advisories/24175Vendor Advisory
- http://secunia.com/advisories/24205Vendor Advisory
- http://secunia.com/advisories/24238Vendor Advisory
- http://secunia.com/advisories/24287Vendor Advisory
- http://secunia.com/advisories/24290Vendor Advisory
- http://secunia.com/advisories/24293Vendor Advisory
- http://secunia.com/advisories/24320Vendor Advisory
- http://secunia.com/advisories/24328Vendor Advisory
- http://secunia.com/advisories/24333Vendor Advisory
- http://secunia.com/advisories/24342Vendor Advisory
- http://secunia.com/advisories/24343Vendor Advisory
- http://secunia.com/advisories/24384Vendor Advisory
- http://secunia.com/advisories/24393Vendor Advisory
- http://secunia.com/advisories/24395Vendor Advisory
- http://secunia.com/advisories/24437Vendor Advisory
- http://secunia.com/advisories/24455Vendor Advisory
- http://secunia.com/advisories/24457Vendor Advisory
- http://secunia.com/advisories/24650Vendor Advisory
- http://www.kb.cert.org/vuls/id/885753US Government Resource
- http://www.redhat.com/support/errata/RHSA-2007-0078.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0079.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0097.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0108.htmlVendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=370445Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0981?
How severe is CVE-2007-0981?
How do I fix CVE-2007-0981?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-0975Variable extraction vulnerability in Ian Bezanson Apache Sta…
- CVE-2007-0976Buffer overflow in the ActSoft DVD-Tools ActiveX control (dv…
- CVE-2007-0977IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for …
- CVE-2007-0978Buffer overflow in swcons in IBM AIX 5.3 allows local users …
- CVE-2007-0979Unspecified vulnerability in LifeType before 1.1.6, and 1.2 …
- CVE-2007-0980Unspecified vulnerability in HP Serviceguard for Linux; pack…
- CVE-2007-0982Cross-site scripting (XSS) vulnerability in error.php in Tas…
- CVE-2007-0983PHP remote file inclusion vulnerability in _admin/nav.php in…
- CVE-2007-0984SQL injection vulnerability in admin_poll.asp in PollMentor …
- CVE-2007-0985SQL injection vulnerability in nickpage.php in phpCC 4.2 bet…
- CVE-2007-0986PHP remote file inclusion vulnerability in index.php in Jupi…
- CVE-2007-0987Directory traversal vulnerability in index.php in Jupiter CM…
Are you affected by CVE-2007-0981?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
