Unrated severityNVD Advisory· Published Apr 11, 2007· Updated Apr 23, 2026
CVE-2007-1970
CVE-2007-1970
Description
Mozilla Firefox does not warn the user about HTTP elements on an HTTPS page when the HTTP elements are dynamically created by a delayed document.write, which allows remote attackers to supply unauthenticated content and conduct phishing attacks.
Affected products
3- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
- osv-coords2 versions
< 0+ 1 more
- (no CPE)range: < 0
- (no CPE)range: < 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.