CVE-2007-1084
published 2007-02-23CVE-2007-1084: Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by…
PriorityP423medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.47%
71.1th percentile
Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of the last visited web page.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | epiphany-browser | — | — |
| mozilla | firefox | <= 2.0.0.1 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2007-1084: epiphany-browser - Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmark...
vendor_debian·2007·CVSS 6.8
CVE-2007-1084 [MEDIUM] CVE-2007-1084: epiphany-browser - Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmark...
Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of the last visited web page.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-3799-mwjc-pmj8: Mozilla Firefox 2
ghsa_unreviewed·2022-05-01
CVE-2007-1084 [MEDIUM] GHSA-3799-mwjc-pmj8: Mozilla Firefox 2
Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of the last visited web page.
OSV
CVE-2007-1084: Mozilla Firefox 2
osv·2007-02-23·CVSS 6.8
CVE-2007-1084 [MEDIUM] CVE-2007-1084: Mozilla Firefox 2
Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of the last visited web page.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-5959 Multiple flaws in Firefox
bugzilla·2007-11-21·CVSS 9.3
CVE-2007-5959 [CRITICAL] CVE-2007-5959 Multiple flaws in Firefox
CVE-2007-5959 Multiple flaws in Firefox
Several flaws were found in the way in which Firefox processed certain
malformed web content. A web page containing malicious content could cause
Firefox to crash or potentially execute arbitrary code as the user running
Firefox.
This fixes the following upstream bugs:
https://bugzilla.mozilla.org/buglist.cgi?bug_id=373911%2C391028%2C393326
Discussion:
Lifting embargo
---
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2007-1084.html
http://rhn.redhat.com/errata/RHSA-2007-1082.html
http://rhn.redhat.com/errata/RHSA-2007-1083.html
Bugzilla
CVE-2007-5947 Mozilla jar: protocol XSS
bugzilla·2007-11-21·CVSS 4.3
CVE-2007-5947 [MEDIUM] CVE-2007-5947 Mozilla jar: protocol XSS
CVE-2007-5947 Mozilla jar: protocol XSS
A cross site scripting flaw was found in the way Firefox handles the jar: URI
scheme. It is possible for a malicious web site to leverage this flaw to
possibly conduct a cross site scripting attack against a Firefox user.
Discussion:
Lifting embargo
---
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2007-1084.html
http://rhn.redhat.com/errata/RHSA-2007-1082.html
http://rhn.redhat.com/errata/RHSA-2007-1083.html
Bugzilla
CVE-2007-5960 Mozilla Cross-site Request Forgery flaw
bugzilla·2007-11-21·CVSS 4.3
CVE-2007-5960 [MEDIUM] CVE-2007-5960 Mozilla Cross-site Request Forgery flaw
CVE-2007-5960 Mozilla Cross-site Request Forgery flaw
A race condition exists when setting the window.location property on a web page.
This flaw could allow a page to set an arbitrary Referer header, which may lead
to a Cross-site Request Forgery (CSRF) attack against websites that rely only on
the Referer header.
Discussion:
Lifting embargo
---
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2007-1084.html
http://rhn.redhat.com/errata/RHSA-2007-1082.html
http://rhn.redhat.com/errata/RHSA-2007-1083.html
http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0490.htmlhttp://lcamtuf.coredump.cx/ffbookhttp://lcamtuf.coredump.cx/ffbook/http://osvdb.org/33803http://securityreason.com/securityalert/2304http://www.heise-security.co.uk/news/85728http://www.securityfocus.com/archive/1/460885/100/0/threadedhttp://www.securityfocus.com/archive/1/460890/100/0/threadedhttp://www.securityfocus.com/archive/1/460896/100/0/threadedhttp://www.securityfocus.com/archive/1/461021/100/0/threadedhttp://www.securityfocus.com/bid/22666https://bugzilla.mozilla.org/show_bug.cgi?id=371179http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0490.htmlhttp://lcamtuf.coredump.cx/ffbookhttp://lcamtuf.coredump.cx/ffbook/http://osvdb.org/33803http://securityreason.com/securityalert/2304http://www.heise-security.co.uk/news/85728http://www.securityfocus.com/archive/1/460885/100/0/threadedhttp://www.securityfocus.com/archive/1/460890/100/0/threadedhttp://www.securityfocus.com/archive/1/460896/100/0/threadedhttp://www.securityfocus.com/archive/1/461021/100/0/threadedhttp://www.securityfocus.com/bid/22666https://bugzilla.mozilla.org/show_bug.cgi?id=371179
2007-02-23
Published