CVE-2007-1084: Medium severity Mozilla Firefox vulnerability
Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of the last visited web page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1084?
CVE-2007-1084 is classified as a high severity vulnerability due to its potential to bypass the same-origin policy.
How do I fix CVE-2007-1084?
To fix CVE-2007-1084, update your Mozilla Firefox to version 2.0.0.2 or later.
What versions of Mozilla Firefox are affected by CVE-2007-1084?
CVE-2007-1084 affects Mozilla Firefox versions 2.0.0.1 and earlier, as well as earlier versions such as 0.8 through 1.5.8.
What does CVE-2007-1084 allow attackers to do?
CVE-2007-1084 allows remote attackers to execute a bookmarklet that bypasses the same-origin policy by tricking a user into saving it.
How can users protect themselves from CVE-2007-1084?
Users can protect themselves from CVE-2007-1084 by avoiding the installation of unknown or untrusted bookmarklets.