Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Benb

#49722of 53,622
5Total CVSS
Vulnerabilities · 1
PT-2007-2543
5.0
2007-02-26
Mozilla · Firefox · CVE-2007-1116
**Name of the Vulnerable Software and Affected Versions** Mozilla Firefox version 1.8 **Description** The issue allows remote attackers to obtain sensitive information by querying the browser's session history. This is due to the CheckLoadURI function listing the about: URI as a ChromeProtocol, which can be loaded via JavaScript. **Recommendations** For Mozilla Firefox version 1.8, consider disabling the CheckLoadURI function or restricting JavaScript access to the about: URI as a temporary workaround until a patch is available.