CVE-2007-3827

NameCVE-2007-3827
DescriptionMozilla Firefox allows for cookies to be set with a null domain (aka "domainless cookies"), which allows remote attackers to pass information between arbitrary domains and track user activity, as demonstrated by the domain attribute in the document.cookie variable in a javascript: window.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Notes

Unreproducible for upstream
https://bugzilla.mozilla.org/show_bug.cgi?id=388097

Search for package or bug name: Reporting problems