Vulnerability Name:

CVE-2002-1126 (CCN-10084)

Assigned:2002-09-11
Published:2002-09-11
Updated:2016-10-18
Summary:Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to determine the next page that is being visited, including manually entered URLs, using the onunload handler.
CVSS v3 Severity:2.9 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
1.2 Low (CCN CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: CCN
Type: BugTraq Mailing List, Wed Sep 11 2002 - 07:51:12 CDT
Privacy leak in mozilla

Source: CCN
Type: Mozilla.org Bugzilla Bug 145579
Website can see url of page visited after it (document referer used when loading images with javascript is incorrect while loading a new page)

Source: CONFIRM
Type: UNKNOWN
http://bugzilla.mozilla.org/show_bug.cgi?id=145579

Source: MITRE
Type: CNA
CVE-2002-1126

Source: BUGTRAQ
Type: UNKNOWN
20020911 Privacy leak in mozilla

Source: CCN
Type: RHSA-2002-192
Updated Mozilla packages fix security vulnerabilities

Source: CCN
Type: RHSA-2003-046
mozilla security update

Source: XF
Type: Vendor Advisory
mozilla-onunload-url-leak(10084)

Source: CCN
Type: Conectiva Linux Security Announcement CLSA-2003:568
mozilla -- several vulnerabilities

Source: MANDRAKE
Type: UNKNOWN
MDKSA-2002:075

Source: REDHAT
Type: Patch, Vendor Advisory
RHSA-2002:192

Source: REDHAT
Type: UNKNOWN
RHSA-2003:046

Source: BID
Type: Exploit, Patch, Vendor Advisory
5694

Source: CCN
Type: BID-5694
Mozilla OnUnload Referer Information Leakage Vulnerability

Source: XF
Type: UNKNOWN
mozilla-onunload-url-leak(10084)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:galeon:galeon_browser:1.2.4:*:*:*:*:*:*:*
  • OR cpe:/a:galeon:galeon_browser:1.2.5:*:*:*:*:*:*:*
  • OR cpe:/a:galeon:galeon_browser:1.2.6:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.3:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.4:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.5:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.6:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.7:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.8:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:0.9.9:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:1.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:mozilla:mozilla:1.0:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:netscape:navigator:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:mozilla:1.1:*:*:*:*:*:*:*
  • AND
  • cpe:/o:conectiva:linux:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.2:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:8.2:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.3:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:as:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:8.2:*:ppc:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    galeon galeon browser 1.2.4
    galeon galeon browser 1.2.5
    galeon galeon browser 1.2.6
    mozilla mozilla 0.9.3
    mozilla mozilla 0.9.4
    mozilla mozilla 0.9.5
    mozilla mozilla 0.9.6
    mozilla mozilla 0.9.7
    mozilla mozilla 0.9.8
    mozilla mozilla 0.9.9
    mozilla mozilla 1.0.1
    mozilla mozilla 1.1
    mozilla mozilla 1.0
    mozilla mozilla 1.0.1
    netscape navigator 7.0
    mozilla mozilla 1.1
    conectiva linux 6.0
    conectiva linux 7.0
    redhat linux 7.2
    mandrakesoft mandrake linux 8.2
    conectiva linux 8.0
    redhat linux 7.3
    redhat linux 8.0
    redhat enterprise linux 2.1
    mandrakesoft mandrake linux 8.2