Vulnerability Name: | CVE-2004-1122 (CCN-17788) | ||||||||
Assigned: | 2004-10-20 | ||||||||
Published: | 2004-10-20 | ||||||||
Updated: | 2008-09-10 | ||||||||
Summary: | Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows, aka the "Dialog Box Spoofing Vulnerability," a different vulnerability than CVE-2004-1314. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Wed Oct 20 2004 - 08:01:31 CDT Secunia Research: Multiple Browsers Tabbed Browsing Vulnerabilities Source: MITRE Type: CNA CVE-2004-1122 Source: CCN Type: AppleCare Knowledge Base Document 61798 Security Update 2004-12-02 Source: APPLE Type: UNKNOWN APPLE-SA-2004-12-02 Source: CCN Type: SA12892 Safari Dialog Box Spoofing Vulnerability Source: SECUNIA Type: UNKNOWN 12892 Source: MISC Type: Vendor Advisory http://secunia.com/multiple_browsers_dialog_box_spoofing_test/ Source: MISC Type: UNKNOWN http://secunia.com/secunia_research/2004-10/ Source: CCN Type: KDE Web site KDE Homepage Source: CCN Type: Opera Web site Opera Web Browser Source: CCN Type: BID-11469 Apple Safari Cross-Domain Dialog Box Spoofing Vulnerability Source: CCN Type: BID-11470 Maxthon Web Browser Cross-Domain Dialog Box Spoofing Vulnerability Source: CCN Type: BID-11472 Avant Browser Cross-Domain Dialog Box Spoofing Vulnerability Source: CCN Type: BID-11473 Mozilla Browser Cross-Domain Dialog Box Spoofing Vulnerability Source: CCN Type: BID-11475 Opera Web Browser Cross-Domain Dialog Box Spoofing Vulnerability Source: CCN Type: BID-11477 Konqueror Browser Cross-Domain Dialog Box Spoofing Vulnerability Source: CCN Type: BID-11519 NetCaptor Cross-Domain Dialog Box Spoofing Vulnerability Source: CCN Type: BID-11531 ICab Web Browser Cross-Domain Dialog Box Spoofing Vulnerability Source: CCN Type: BID-11532 Slim Browser Cross-Domain Dialog Box Spoofing Vulnerability Source: CCN Type: BID-11544 Omni Group OmniWeb Browser Cross-Domain Dialog Box Spoofing Vulnerability Source: XF Type: UNKNOWN web-browser-dialog-spoofing(17788) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |