[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-1753Date: (C)2004-12-31   (M)2023-12-22


The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.6
Exploit Score: 4.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
BID-11059
SECUNIA-12392
http://www.securityfocus.com/archive/1/373080
http://www.securityfocus.com/archive/1/373232
http://bugzilla.mozilla.org/show_bug.cgi?id=162134
netscape-java-tab-spoofing(17137)

CPE    4
cpe:/a:mozilla:mozilla:1.7.2
cpe:/a:netscape:navigator:7.2
cpe:/a:netscape:navigator:7.1
cpe:/a:mozilla:firefox:0.9.3
...

© SecPod Technologies