CVE-2005-2266: Medium severity Mozilla Firefox vulnerability
Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2266?
CVE-2005-2266 is classified as a medium-severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2005-2266?
To fix CVE-2005-2266, upgrade to Mozilla Firefox version 1.0.5 or later and Mozilla version 1.7.9 or later.
What does CVE-2005-2266 exploit?
CVE-2005-2266 exploits a flaw in the same origin policy, allowing a child frame to access elements in a parent frame from a different domain.
What types of information can be stolen due to CVE-2005-2266?
CVE-2005-2266 can allow remote attackers to steal sensitive information such as cookies and passwords.
Which versions are affected by CVE-2005-2266?
CVE-2005-2266 affects various versions of Mozilla Firefox prior to 1.0.5 and various versions of Mozilla prior to 1.7.9.