Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2004-1381Mozilla Firefox vulnerability

6 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
15.3%
top 5.37%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedOct 20
Latest updateApr 29

Description

Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers to steal sensitive data that is intended for other sites, which could facilitate phishing attacks.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDmozilla/firefox7 versions+6
NVDmozilla/mozilla10 versions+9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hhqx-qfww-wwhc: Firefox before 12022-04-29
CVEList
CVE-2004-1381: Firefox before 12005-01-29

💥Exploits & PoCs

1
Exploit-DB
Multiple Browsers - Tabbed Browsing2004-10-22

📋Vendor Advisories

1
Ubuntu
Ubuntu 4.10 update for Firefox vulnerabilities2005-07-28

💬Community

1
Bugzilla
CVE-2004-1380 Input stealing from other tabs (CVE-2004-1381)2005-03-23