Mozilla: Privacy leak and other vulnerabilities
| Package(s): | mozilla | CVE #(s): | CAN-2002-1126 CAN-2002-1091 | ||||||||
| Created: | November 1, 2002 | Updated: | February 13, 2003 | ||||||||
| Description: | Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and
Galeon, set the document referrer too quickly in certain situations when a
new page is being loaded, which allows web pages to determine the next page
that is being visited, including manually entered URLs.
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width. See also Mozilla's Recently fixed security issues page. All users are encouraged to upgrade to this latest stable 1.0.x release of Mozilla. | ||||||||||
| Alerts: |
| ||||||||||
