CVE-2002-2013: Medium severity Mozilla Mozilla vulnerability
Published Dec 31, 2002
·Updated
Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
Affected Software
30 affected components
Mozilla Mozilla=0.9.5
Netscape Navigator=6.2
Netscape Communicator=4.76
Netscape Navigator=6.0
Netscape Communicator=4.77
Mozilla Mozilla=0.9.3
Netscape Communicator=4.61
Netscape Communicator=4.07
Netscape Communicator=4.73
Netscape Communicator=4.51
Netscape Communicator=4.4
Mozilla Mozilla=0.9.2.1
Netscape Communicator=4.06
Mozilla Mozilla=0.9.2
Netscape Communicator=4.7
Netscape Communicator=4.78
Netscape Communicator=4.0
Mozilla Mozilla=0.9.4
Netscape Communicator=4.74
Netscape Communicator=4.08
Netscape Communicator=4.6
Netscape Communicator=4.5_beta
Netscape Navigator=6.01
Netscape Communicator=4.72
Mozilla Mozilla=0.9.6
Netscape Communicator=4.5
Mozilla Mozilla=0.9.4.1
Netscape Navigator=6.1
Netscape Navigator=4.77
Netscape Communicator=4.75
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Jul 14, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2013?
CVE-2002-2013 is considered a high-severity vulnerability due to its ability to steal cookies from other domains.
2
How do I fix CVE-2002-2013?
To mitigate CVE-2002-2013, upgrade to the latest version of Mozilla or Netscape that is not affected by this vulnerability.
3
Which versions of Mozilla are affected by CVE-2002-2013?
CVE-2002-2013 affects Mozilla versions 0.9.6 and earlier.
4
Which versions of Netscape are impacted by CVE-2002-2013?
Netscape Navigator versions 6.2 and earlier, as well as earlier versions of Netscape Communicator, are vulnerable to CVE-2002-2013.
5
What type of attack does CVE-2002-2013 facilitate?
CVE-2002-2013 allows remote attackers to exploit a cookie theft attack through a specially crafted link.