CVE-2007-1256
Last modified
CVE-2007-1256 is a vulnerability of currently unknown severity. Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitrary websites, by repeatedly setting document.location in the onunload attribute when linking to another website, a variant of CVE-2007-1092.. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitrary websites, by repeatedly setting document.location in the onunload attribute when linking to another website, a variant of CVE-2007-1092.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 2.0 |
| Mozilla | Firefox | 2.0.0.1 |
| Mozilla | Firefox | 2.0.0.2 |
References
- http://marc.info/?l=full-disclosure&m=117258301222007&w=2Third Party Advisory
- http://marc.info/?l=full-disclosure&m=117259225402112&w=2Third Party Advisory
- http://osvdb.org/35913Broken Link
- http://marc.info/?l=full-disclosure&m=117258301222007&w=2Third Party Advisory
- http://marc.info/?l=full-disclosure&m=117259225402112&w=2Third Party Advisory
- http://osvdb.org/35913Broken Link
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1256?
How severe is CVE-2007-1256?
How do I fix CVE-2007-1256?
Are you affected by CVE-2007-1256?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
