Back

CVE-2004-1122

Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows, aka the "Dialog Box Spoofing Vulnerability," a different vulnerability than CVE-2004-1314.

Published: Jan 10, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
apple safari 1.2.3

GitHub Security Advisory GHSA-fjjm-8r2x-qmqx

Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes,...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.34%

Top 18% most likely to be exploited

Threat Score 30.7 / 100

Data Sources

NVD EPSS GitHub