Vulnerability Name: | CVE-2004-1381 (CCN-17789) |
Assigned: | 2004-10-20 |
Published: | 2004-10-20 |
Updated: | 2017-10-11 |
Summary: | Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers to steal sensitive data that is intended for other sites, which could facilitate phishing attacks.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): None Availibility (A): None |
|
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None |
|
Vulnerability Type: | CWE-Other
|
Vulnerability Consequences: | Obtain Information |
References: | Source: CCN Type: Full-Disclosure Mailing List, Wed Oct 20 2004 - 08:01:31 CDT Secunia Research: Multiple Browsers Tabbed Browsing Vulnerabilities
Source: MITRE Type: CNA CVE-2004-1381
Source: CCN Type: SA12712 Mozilla / Mozilla Firefox / Camino Tabbed Browsing Vulnerabilities
Source: SECUNIA Type: Exploit, Patch, Vendor Advisory 12712
Source: MISC Type: Vendor Advisory http://secunia.com/multiple_browsers_dialog_box_spoofing_test/
Source: MISC Type: Vendor Advisory http://secunia.com/multiple_browsers_form_field_focus_test/
Source: CONFIRM Type: Patch, Vendor Advisory http://www.mozilla.org/security/announce/mfsa2005-05.html
Source: CCN Type: BID-11474 Mozilla Browser Cross-Domain Tab Window Form Field Focus Vulnerability
Source: CCN Type: BID-11476 Maxthon Web Browser Cross-Domain Tab Window Form Field Focus Vulnerability
Source: CCN Type: BID-11478 Avant Browser Cross-Domain Tab Window Form Field Focus Vulnerability
Source: CCN Type: BID-11520 NetCaptor Cross-Domain Tab Window Form Field Focus Vulnerability
Source: CCN Type: BID-11530 Slim Browser Cross-Domain Tab Window Form Field Focus Vulnerability
Source: CCN Type: USN-149-3 Ubuntu 4.10 update for Firefox vulnerabilities
Source: XF Type: UNKNOWN web-browser-inactive-info-disclosure(17789)
Source: XF Type: UNKNOWN web-browser-inactive-info-disclosure(17789)
Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:100053
|
Vulnerable Configuration: | Configuration 1: cpe:/a:mozilla:firefox:0.8:*:*:*:*:*:*:*OR cpe:/a:mozilla:firefox:0.9:*:*:*:*:*:*:*OR cpe:/a:mozilla:firefox:0.9:rc:*:*:*:*:*:*OR cpe:/a:mozilla:firefox:0.9.1:*:*:*:*:*:*:*OR cpe:/a:mozilla:firefox:0.9.2:*:*:*:*:*:*:*OR cpe:/a:mozilla:firefox:0.9.3:*:*:*:*:*:*:*OR cpe:/a:mozilla:firefox:0.10:*:*:*:*:*:*:*OR cpe:/a:mozilla:firefox:0.10.1:*:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:*:*:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.3:*:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.4:*:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.4:alpha:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.4.1:*:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.5:*:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.5:alpha:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.5:rc1:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.5:rc2:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.5.1:*:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.6:*:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.6:alpha:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.6:beta:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.7:*:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.7:alpha:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.7:beta:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.7:rc1:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.7:rc2:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.7:rc3:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.7.1:*:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.7.2:*:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.7.3:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:netscape:navigator:7.2:*:*:*:*:*:*:*OR cpe:/a:mozilla:mozilla:1.7.3:*:*:*:*:*:*:*OR cpe:/a:mozilla:firefox:0.10.1:*:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |