Most browsers have a setting to disable 'third party cookies' - e.g. if you're on www.evil.com and that page sends a request to www.example.com the example.com connection won't send cookies, or store received cookies.
You can set this up easily in Firefox [1] and Chrome [2]. It will break a handful of things, for example some sites embed comments from facebook, disqus, google+ etc. So for example when you visit www.youtube.com you won't be able to comment, as comments are in iframe loaded from plus.google.com which you can't log into without third party cookies enabled.
IMHO this is no great loss, and I block third party cookies all the time.
Of course, it's still possible to do certain attacks by redirecting the entire browser window or opening a popup window.
[1] https://support.mozilla.org/en-US/kb/disable-third-party-coo...
[2] https://support.google.com/chrome/answer/95647?hl=en-GB