New Search

Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI which allows remote attackers to obtain sensitive information poison the browser cache and possibly enable further attack vectors via (1) HTTP 302 redirect controls (2) XMLHttpRequest or (3) view-source URIs.

oval:org.mitre.oval:def:9105

Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI which allows remote attackers to obtain sensitive information poison the browser cache and possibly enable further attack vectors via (1) HTTP 302 redirect controls (2) XMLHttpRequest or (3) view-source URIs.

Family:
unix
Status:
ACCEPTED
Platform(s):
  • Red Hat Enterprise Linux 3
  • Oracle Linux 4
  • Red Hat Enterprise Linux 5
  • CentOS Linux 3
  • Oracle Linux 5
  • Red Hat Enterprise Linux 4
  • CentOS Linux 4
  • CentOS Linux 5
Class:
vulnerability
Reference(s):
  • CVE-2007-3656
Product(s):