CVE Vulnerabilities

CVE-2004-0191

Published: Mar 15, 2004 | Modified: Oct 10, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.

Affected Software

Name Vendor Start Version End Version
Mozilla Mozilla 0.8 0.8
Mozilla Mozilla 0.9.2 0.9.2
Mozilla Mozilla 0.9.2.1 0.9.2.1
Mozilla Mozilla 0.9.3 0.9.3
Mozilla Mozilla 0.9.4 0.9.4
Mozilla Mozilla 0.9.4.1 0.9.4.1
Mozilla Mozilla 0.9.5 0.9.5
Mozilla Mozilla 0.9.6 0.9.6
Mozilla Mozilla 0.9.7 0.9.7
Mozilla Mozilla 0.9.8 0.9.8
Mozilla Mozilla 0.9.9 0.9.9
Mozilla Mozilla 0.9.35 0.9.35
Mozilla Mozilla 0.9.48 0.9.48
Mozilla Mozilla 1.0 1.0
Mozilla Mozilla 1.0 1.0
Mozilla Mozilla 1.0 1.0
Mozilla Mozilla 1.0.1 1.0.1
Mozilla Mozilla 1.0.2 1.0.2
Mozilla Mozilla 1.1 1.1
Mozilla Mozilla 1.1 1.1
Mozilla Mozilla 1.1 1.1
Mozilla Mozilla 1.2 1.2
Mozilla Mozilla 1.2 1.2
Mozilla Mozilla 1.2 1.2
Mozilla Mozilla 1.2.1 1.2.1
Mozilla Mozilla 1.3 1.3
Mozilla Mozilla 1.3.1 1.3.1
Mozilla Mozilla 1.4 1.4
Mozilla Mozilla 1.4 1.4
Mozilla Mozilla 1.4 1.4
Mozilla Mozilla 1.4.1 1.4.1
Mozilla Mozilla 1.5 1.5
Red Hat Enterprise Linux 2.1 RedHat galeon *
Red Hat Enterprise Linux 2.1 RedHat mozilla *
Red Hat Enterprise Linux 3 RedHat mozilla *
Red Hat Linux 9 RedHat mozilla *

References