CVE-2007-1256
Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitrary websites, by repeatedly setting document.location in the onunload attribute when linking to another…
Does this matter?
Lower severity and a low EPSS score (1.01%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitrary websites, by repeatedly setting document.location in the onunload attribute when linking to another website, a variant of CVE-2007-1092.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.01% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- mozilla/firefox
- Source
- cve@mitre.org
References
- http://marc.info/?l=full-disclosure&m=117258301222007&w=2Third Party Advisory
- http://marc.info/?l=full-disclosure&m=117259225402112&w=2Third Party Advisory
- http://osvdb.org/35913Broken Link
- http://www.securityfocus.com/archive/1/461437/100/0/threaded
- http://marc.info/?l=full-disclosure&m=117258301222007&w=2Third Party Advisory
- http://marc.info/?l=full-disclosure&m=117259225402112&w=2Third Party Advisory
- http://osvdb.org/35913Broken Link
- http://www.securityfocus.com/archive/1/461437/100/0/threaded
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.