CVE-2007-2871: Medium severity Mozilla Firefox vulnerability
Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to spoof or hide the browser chrome, such as the location bar, by placing XUL popups outside of the browser's content pane. NOTE: this issue can be leveraged for phishing and other attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2871?
CVE-2007-2871 is categorized as a moderate severity vulnerability that can be exploited for phishing attacks.
How do I fix CVE-2007-2871?
To resolve CVE-2007-2871, upgrade to Mozilla Firefox version 1.5.0.12 or 2.0.0.4 or later.
Which software versions are affected by CVE-2007-2871?
CVE-2007-2871 affects Mozilla Firefox versions 1.5.x before 1.5.0.12, all 2.x versions before 2.0.0.4, and SeaMonkey versions 1.0.9 and 1.1.2.
What type of attack can exploit CVE-2007-2871?
CVE-2007-2871 can be exploited to spoof or hide the browser chrome, facilitating phishing attacks.
Is there a workaround for CVE-2007-2871?
There is no official workaround for CVE-2007-2871 other than upgrading to a patched version of the affected software.