6.8
CVSSv2

CVE-2007-1084

Published: 23/02/2007 Updated: 16/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Mozilla Firefox 2.0.0.1 and previous versions does not prompt users before saving bookmarklets, which allows remote malicious users to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of the last visited web page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 0.9

mozilla firefox 0.9.1

mozilla firefox 1.0.4

mozilla firefox 1.0.5

mozilla firefox 1.5.0.4

mozilla firefox 1.5.0.5

mozilla firefox 2.0

mozilla firefox

mozilla firefox 0.10.1

mozilla firefox 0.8

mozilla firefox 1.0.2

mozilla firefox 1.0.3

mozilla firefox 1.5.0.1

mozilla firefox 1.5.0.2

mozilla firefox 1.5.0.3

mozilla firefox 1.5.6

mozilla firefox 1.5.8

mozilla firefox 0.9.2

mozilla firefox 0.9.3

mozilla firefox 1.0.6

mozilla firefox 1.0.7

mozilla firefox 1.5.0.6

mozilla firefox 1.5.0.7

mozilla firefox 0.10

mozilla firefox 1.0

mozilla firefox 1.0.1

mozilla firefox 1.0.8

mozilla firefox 1.5

mozilla firefox 1.5.0.8

mozilla firefox 1.5.0.9

Vendor Advisories

Debian Bug report logs - #556268 iceweasel: CVE-2007-1084 bookmarklets cross-site information disclosure Package: iceweasel; Maintainer for iceweasel is Maintainers of Mozilla-related packages <team+pkg-mozilla@trackerdebianorg>; Source for iceweasel is src:firefox-esr (PTS, buildd, popcon) Reported by: Michael Gilbert &lt ...