Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the windows titlebar when displaying XUL markup language documents, which makes it easier for remote attackers to conduct phishing and spoofing attacks by setting the hidechrome attribute.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | * | 2.0.0.7 (including) |
Seamonkey | Mozilla | * | 1.1.4 (including) |
Red Hat Enterprise Linux 2.1 | RedHat | seamonkey-0:1.0.9-0.6.el2 | * |
Red Hat Enterprise Linux 3 | RedHat | seamonkey-0:1.0.9-0.5.el3 | * |
Red Hat Enterprise Linux 4 | RedHat | firefox-0:1.5.0.12-0.7.el4 | * |
Red Hat Enterprise Linux 4 | RedHat | seamonkey-0:1.0.9-6.el4 | * |
Red Hat Enterprise Linux 4 | RedHat | thunderbird-0:1.5.0.12-0.5.el4 | * |
Red Hat Enterprise Linux 5 | RedHat | firefox-0:1.5.0.12-6.el5 | * |
Red Hat Enterprise Linux 5 | RedHat | thunderbird-0:1.5.0.12-5.el5 | * |
Firefox | Ubuntu | dapper | * |
Firefox | Ubuntu | edgy | * |
Firefox | Ubuntu | feisty | * |
Firefox | Ubuntu | gutsy | * |
Firefox | Ubuntu | upstream | * |
Mozilla-thunderbird | Ubuntu | dapper | * |
Mozilla-thunderbird | Ubuntu | edgy | * |
Mozilla-thunderbird | Ubuntu | feisty | * |
Thunderbird | Ubuntu | gutsy | * |
Thunderbird | Ubuntu | upstream | * |