Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2004-2491Race Condition in Browser

Severity
2.6LOWNVD
EPSS
10.4%
top 6.77%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedDec 31
Latest updateApr 29

Description

A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing attacks.

CVSS vector

AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6rch-h7pj-5838: A race condition in Opera web browser 72022-04-29
CVEList
CVE-2004-2491: A race condition in Opera web browser 72005-10-25

💥Exploits & PoCs

1
Exploit-DB
Opera Web Browser 7.53 - Location Replace URI Obfuscation2004-07-27

📐Framework References

1
CWE
Context Switching Race Condition
CVE-2004-2491 — Race Condition in Opera Browser | cvebase