CVE-2007-0981
Last modified
CVE-2007-0981 is a vulnerability of currently unknown severity. Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.. EPSS estimates a 12.14% chance of exploitation in the next 30 days.
Description
Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | <= 1.5.0.9 |
| Mozilla | Firefox | 0.8 |
| Mozilla | Firefox | 0.9 |
| Mozilla | Firefox | 0.9.1 |
| Mozilla | Firefox | 0.9.2 |
| Mozilla | Firefox | 0.9.3 |
| Mozilla | Firefox | 0.10 |
| Mozilla | Firefox | 0.10.1 |
| Mozilla | Firefox | 1.0 |
| Mozilla | Firefox | 1.0.1 |
| Mozilla | Firefox | 1.0.2 |
| Mozilla | Firefox | 1.0.3 |
| Mozilla | Firefox | 1.0.4 |
| Mozilla | Firefox | 1.0.5 |
| Mozilla | Firefox | 1.0.6 |
| Mozilla | Firefox | 1.0.7 |
| Mozilla | Firefox | 1.0.8 |
| Mozilla | Firefox | 1.5 |
| Mozilla | Firefox | 1.5.0.1 |
| Mozilla | Firefox | 1.5.0.2 |
| Mozilla | Firefox | 1.5.0.3 |
| Mozilla | Firefox | 1.5.0.4 |
| Mozilla | Firefox | 1.5.0.5 |
| Mozilla | Firefox | 1.5.0.6 |
| Mozilla | Firefox | 1.5.0.7 |
| Mozilla | Firefox | 1.5.0.8 |
| Mozilla | Firefox | 1.5.1 |
| Mozilla | Firefox | 1.5.2 |
| Mozilla | Firefox | 1.5.3 |
| Mozilla | Firefox | 1.5.4 |
| Mozilla | Firefox | 1.5.5 |
| Mozilla | Firefox | 1.5.6 |
| Mozilla | Firefox | 1.5.7 |
| Mozilla | Firefox | 1.5.8 |
| Mozilla | Firefox | 2.0 |
| Mozilla | Firefox | 2.0.0.1 |
| Mozilla | Firefox | preview_release |
| Mozilla | Seamonkey | <= 1.0.7 |
| Mozilla | Seamonkey | 1.0 |
| Mozilla | Seamonkey | 1.0.1 |
| Mozilla | Seamonkey | 1.0.2 |
| Mozilla | Seamonkey | 1.0.3 |
| Mozilla | Seamonkey | 1.0.4 |
| Mozilla | Seamonkey | 1.0.5 |
| Mozilla | Seamonkey | 1.0.6 |
References
- http://rhn.redhat.com/errata/RHSA-2007-0077.htmlVendor Advisory
- http://secunia.com/advisories/24175Vendor Advisory
- http://secunia.com/advisories/24205Vendor Advisory
- http://secunia.com/advisories/24238Vendor Advisory
- http://secunia.com/advisories/24287Vendor Advisory
- http://secunia.com/advisories/24290Vendor Advisory
- http://secunia.com/advisories/24293Vendor Advisory
- http://secunia.com/advisories/24320Vendor Advisory
- http://secunia.com/advisories/24328Vendor Advisory
- http://secunia.com/advisories/24333Vendor Advisory
- http://secunia.com/advisories/24342Vendor Advisory
- http://secunia.com/advisories/24343Vendor Advisory
- http://secunia.com/advisories/24384Vendor Advisory
- http://secunia.com/advisories/24393Vendor Advisory
- http://secunia.com/advisories/24395Vendor Advisory
- http://secunia.com/advisories/24437Vendor Advisory
- http://secunia.com/advisories/24455Vendor Advisory
- http://secunia.com/advisories/24457Vendor Advisory
- http://secunia.com/advisories/24650Vendor Advisory
- http://www.kb.cert.org/vuls/id/885753US Government Resource
- http://www.redhat.com/support/errata/RHSA-2007-0078.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0079.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0097.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0108.htmlVendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=370445Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2007-0077.htmlVendor Advisory
- http://secunia.com/advisories/24175Vendor Advisory
- http://secunia.com/advisories/24205Vendor Advisory
- http://secunia.com/advisories/24238Vendor Advisory
- http://secunia.com/advisories/24287Vendor Advisory
- http://secunia.com/advisories/24290Vendor Advisory
- http://secunia.com/advisories/24293Vendor Advisory
- http://secunia.com/advisories/24320Vendor Advisory
- http://secunia.com/advisories/24328Vendor Advisory
- http://secunia.com/advisories/24333Vendor Advisory
- http://secunia.com/advisories/24342Vendor Advisory
- http://secunia.com/advisories/24343Vendor Advisory
- http://secunia.com/advisories/24384Vendor Advisory
- http://secunia.com/advisories/24393Vendor Advisory
- http://secunia.com/advisories/24395Vendor Advisory
- http://secunia.com/advisories/24437Vendor Advisory
- http://secunia.com/advisories/24455Vendor Advisory
- http://secunia.com/advisories/24457Vendor Advisory
- http://secunia.com/advisories/24650Vendor Advisory
- http://www.kb.cert.org/vuls/id/885753US Government Resource
- http://www.redhat.com/support/errata/RHSA-2007-0078.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0079.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0097.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0108.htmlVendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=370445Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0981?
How severe is CVE-2007-0981?
How do I fix CVE-2007-0981?
Are you affected by CVE-2007-0981?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
