CVE-2002-1126Browser vulnerability

6 documents5 sources
Severity
2.6LOWNVD
EPSS
0.5%
top 32.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24
Latest updateApr 30

Description

Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to determine the next page that is being visited, including manually entered URLs, using the onunload handler.

CVSS vector

AV:N/AC:H/C:P/I:N/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages2 packages

NVDmozilla/mozilla9 versions+8
NVDgaleon/galeon_browser1.2.4, 1.2.5, 1.2.6+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x37x-6gcq-9wg8: Mozilla 12022-04-30
CVEList
CVE-2002-1126: Mozilla 12004-09-01

📋Vendor Advisories

1
Red Hat
security flaw2002-05-19

💬Community

2
Bugzilla
CVE-2002-1126 security flaw2018-08-16
Bugzilla
CVE-2007-5275 Flash plugin DNS rebinding2007-11-05
CVE-2002-1126 — Galeon Browser vulnerability | cvebase