CVE-2002-1126
Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to determine the next page that is being visited,…
Does this matter?
Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to determine the next page that is being visited, including manually entered URLs, using the onunload handler.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
- EPSS
- 1.52% probability · 73th percentile
- CISA KEV
- Not listed
- Affected
- galeon/galeon browser · mozilla/mozilla
- Source
- cve@mitre.org
References
- http://bugzilla.mozilla.org/show_bug.cgi?id=145579
- http://marc.info/?l=bugtraq&m=103176760004720&w=2
- http://www.iss.net/security_center/static/10084.phpVendor Advisory
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:075
- http://www.redhat.com/support/errata/RHSA-2002-192.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2003-046.html
- http://www.securityfocus.com/bid/5694Exploit, Patch, Vendor Advisory
- http://bugzilla.mozilla.org/show_bug.cgi?id=145579
- http://marc.info/?l=bugtraq&m=103176760004720&w=2
- http://www.iss.net/security_center/static/10084.phpVendor Advisory
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:075
- http://www.redhat.com/support/errata/RHSA-2002-192.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2003-046.html
- http://www.securityfocus.com/bid/5694Exploit, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.