Lucene search

K
cveMitreCVE-2004-1753
HistoryFeb 26, 2005 - 5:00 a.m.

CVE-2004-1753

2005-02-2605:00:00
mitre
web.nvd.nist.gov
25
apple
java
plugin
netscape
mozilla
firefox
macos x
tabbed browsing
setwindow
phishing
cve-2004-1753

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.006

Percentile

78.6%

The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs.

Affected configurations

Nvd
Node
mozillafirefoxMatch0.9.3
OR
mozillamozillaMatch1.7.2
OR
netscapenavigatorMatch7.1
OR
netscapenavigatorMatch7.2
VendorProductVersionCPE
mozillafirefox0.9.3cpe:2.3:a:mozilla:firefox:0.9.3:*:*:*:*:*:*:*
mozillamozilla1.7.2cpe:2.3:a:mozilla:mozilla:1.7.2:*:*:*:*:*:*:*
netscapenavigator7.1cpe:2.3:a:netscape:navigator:7.1:*:*:*:*:*:*:*
netscapenavigator7.2cpe:2.3:a:netscape:navigator:7.2:*:*:*:*:*:*:*

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.006

Percentile

78.6%

Related for CVE-2004-1753