Loading...
Loading...
Mozilla does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."
September 16, 2004
April 16, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2004-0871
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.