Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2004-1158

Опубликовано: 10 янв. 2005
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.

РелизСтатусПримечание
dapper

released

3.5.2-0ubuntu27.1
devel

released

3.5.7-1ubuntu23
edgy

released

3.5.5-0ubuntu3.5
feisty

released

3.5.6-0ubuntu20.2
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

3.5.2-0ubuntu18.5
devel

released

3.5.7-1ubuntu14
edgy

released

3.5.5-0ubuntu3.5
feisty

released

3.5.6-0ubuntu14.1
upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 88%
0.03863
Низкий

7.5 High

CVSS2

Связанные уязвимости

redhat
больше 20 лет назад

Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.

nvd
больше 20 лет назад

Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.

debian
больше 20 лет назад

Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remot ...

github
больше 3 лет назад

Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.

fstec
больше 20 лет назад

Уязвимости операционной системы Red Hat Enterprise Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 88%
0.03863
Низкий

7.5 High

CVSS2