peter bassill · operator
$ cve CVE-2007-0981 JSON

CVE-2007-0981 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 12.5% (pctl 96)

Patch early

A public exploit exists.

Description

Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS12.52% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2007-02-16
Last modified2026-06-16

Affected (2)

VendorProduct
mozillafirefox
mozillaseamonkey

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD