CVE-2002-2013

Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.

Scoring

CVSS base score
0.02
EPSS probability
0.48%
Published
2005-07-14
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs