Back
CVE-2004-1380
Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows and facilitate phishing attacks, aka the "Dialog Box Spoofing Vulnerability."
Published: Oct 20, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (30)
| Vendor | Product | Version |
|---|---|---|
| mozilla | firefox | 0.8 |
| mozilla | firefox | 0.9 |
| mozilla | firefox | 0.9 |
| mozilla | firefox | 0.9.1 |
| mozilla | firefox | 0.9.2 |
| mozilla | firefox | 0.9.3 |
| mozilla | firefox | 0.10 |
| mozilla | firefox | 0.10.1 |
| mozilla | mozilla | * |
| mozilla | mozilla | 1.3 |
| mozilla | mozilla | 1.4 |
| mozilla | mozilla | 1.4 |
| mozilla | mozilla | 1.4.1 |
| mozilla | mozilla | 1.5 |
| mozilla | mozilla | 1.5 |
| mozilla | mozilla | 1.5 |
| mozilla | mozilla | 1.5 |
| mozilla | mozilla | 1.5.1 |
| mozilla | mozilla | 1.6 |
| mozilla | mozilla | 1.6 |
…and 10 more
GitHub Security Advisory GHSA-vv9m-2w98-m7rf
Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog...
References (18)
- http://secunia.com/advisories/12712 Patch, Vendor Advisory
- http://secunia.com/multiple_browsers_dialog_box_spoofing_test/ Vendor Advisory
- http://secunia.com/multiple_browsers_form_field_focus_test/ Vendor Advisory
- http://www.mozilla.org/security/announce/mfsa2005-05.html Patch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-323.html Patch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-335.html Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18864
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100050
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10211
- http://secunia.com/advisories/12712 Patch, Vendor Advisory
- http://secunia.com/multiple_browsers_dialog_box_spoofing_test/ Vendor Advisory
- http://secunia.com/multiple_browsers_form_field_focus_test/ Vendor Advisory
- http://www.mozilla.org/security/announce/mfsa2005-05.html Patch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-323.html Patch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-335.html Patch, Vendor Advisory
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
3.68%
Top 11% most likely to be exploited
Threat Score
21.1 / 100
Data Sources
NVD
EPSS
GitHub