HomeGoogleCVE-2007-6536

CVE-2007-6536

UNKNOWN
6.8CVSS
Published: 2007-12-27
Updated: 2025-04-09
AI Analysis

Description

The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names in the (1) "Downloaded from" and (2) "Privacy considerations" sections without verifying domain names, which makes it easier for remote attackers to spoof domain names and trick users into installing malicious button XML files, as demonstrated by presenting www.google.com when the button was downloaded from an arbitrary site through an open redirector on www.google.com.

CVSS Metrics

Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Access Vector
network
Access Cmplx
medium
Auth
none
Confidentiality
partial
Integrity
partial
Availability
partial
Weaknesses
CWE-200

Metadata

Primary Vendor
GOOGLE
Published
12/27/2007
Last Modified
4/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

google : toolbargoogle : toolbar

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2007-6536 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com