{"id":"DEBIAN-CVE-2007-1084","details":"Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of the last visited web page.","modified":"2026-09-01T20:02:31.916810798Z","published":"2007-02-23T02:28:00Z","upstream":["CVE-2007-1084"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2007-1084"}],"affected":[{"package":{"name":"epiphany-browser","ecosystem":"Debian:12","purl":"pkg:deb/debian/epiphany-browser?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["43.1-1","44.0-1","44.1-1","44.2-1","44.3-1","44.5-1","44.5-2","44.6-1","44~rc-1","45.0-1","45.1-1","45.2-1","45~beta-1","46.0-1","46.0-2","46.1-1","46.2-1","46.3-1","46~alpha-1","46~beta-1","47.0-1","47.2-1","47~beta-1","47~rc-1","48.0-1","48.1-1","48.2-1","48.3-1","48.3-2","48.5-1","48.5-2","48.5-3","48~beta-1","48~rc-1","48~rc-2","49.0-1","49.1-1","49.2-1","49.2-2","49.2-3","50.3-1","50.3-2","50.4-1","50.4-2","51~rc-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2007-1084.json"}},{"package":{"name":"epiphany-browser","ecosystem":"Debian:13","purl":"pkg:deb/debian/epiphany-browser?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["48.3-2","48.5-0+deb13u1","48.5-1","48.5-2","48.5-3","49.0-1","49.1-1","49.2-1","49.2-2","49.2-3","50.3-1","50.3-2","50.4-1","50.4-2","51~rc-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2007-1084.json"}},{"package":{"name":"epiphany-browser","ecosystem":"Debian:14","purl":"pkg:deb/debian/epiphany-browser?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["48.3-2","48.5-1","48.5-2","48.5-3","49.0-1","49.1-1","49.2-1","49.2-2","49.2-3","50.3-1","50.3-2","50.4-1","50.4-2","51~rc-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2007-1084.json"}}],"schema_version":"1.9.0"}