CVE-2004-0909
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 may allow remote attackers to trick users into performing unexpected actions, including installing software, via signed scripts that request enhanced abilities using the enablePrivilege parameter, then modify the meaning of certain security-relevant dialog messages.
- Affected products
- Mozilla Firefox, Firefox, Thunderbird
- Mozilla
- = 0.8, 0.9.2, 0.9.2.1, 0.9.3, 0.9.4, 0.9.4.1, 0.9.5, 0.9.6, 0.9.7, 0.9.8, 0.9.9, 0.9.35, 0.9.48, 1.0, 1.0.1, 1.0.2, 1.1, 1.2, 1.2.1, 1.3, 1.3.1, 1.4, 1.4.1, 1.4.2, 1.4.4, 1.5, 1.5.1, 1.6, 1.7, 1.7.1, 1.7.2
- Mozilla Thunderbird
- = 0.1, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.7.1, 0.7.2
- Fix
- Available
- CVSS 2.0
- 5.1 MEDIUM
- EPSS
- 1.7% (75th percentile)
- NVD status
- Modified
- Published
- 2004-09-24
CVE-2004-0909 at NVD
No indexed exploits for CVE-2004-0909 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2004-0909 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.