CVE-2007-2871: Medium severity Mozilla Firefox vulnerability

Published Jun 1, 2007
·
Updated

Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to spoof or hide the browser chrome, such as the location bar, by placing XUL popups outside of the browser's content pane. NOTE: this issue can be leveraged for phishing and other attacks.

Affected Software

18 affected components
Mozilla Firefox=1.5
Mozilla Firefox=1.5.0.1
Mozilla Firefox=1.5.0.2
Mozilla Firefox=1.5.0.3
Mozilla Firefox=1.5.0.4
Mozilla Firefox=1.5.0.5
Mozilla Firefox=1.5.0.6
Mozilla Firefox=1.5.0.7
Mozilla Firefox=1.5.0.8
Mozilla Firefox=1.5.0.9
Mozilla Firefox=1.5.0.10
Mozilla Firefox=1.5.0.11
Mozilla Firefox=2.0
Mozilla Firefox=2.0.0.1
Mozilla Firefox=2.0.0.2
Mozilla Firefox=2.0.0.3
Mozilla SeaMonkey=1.0.9
Mozilla SeaMonkey=1.1.2

Event History

Jun 1, 2007
CVE Published
12:30 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2007-2871?

CVE-2007-2871 is categorized as a moderate severity vulnerability that can be exploited for phishing attacks.

2

How do I fix CVE-2007-2871?

To resolve CVE-2007-2871, upgrade to Mozilla Firefox version 1.5.0.12 or 2.0.0.4 or later.

3

Which software versions are affected by CVE-2007-2871?

CVE-2007-2871 affects Mozilla Firefox versions 1.5.x before 1.5.0.12, all 2.x versions before 2.0.0.4, and SeaMonkey versions 1.0.9 and 1.1.2.

4

What type of attack can exploit CVE-2007-2871?

CVE-2007-2871 can be exploited to spoof or hide the browser chrome, facilitating phishing attacks.

5

Is there a workaround for CVE-2007-2871?

There is no official workaround for CVE-2007-2871 other than upgrading to a patched version of the affected software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203