7.5
CVSSv2

CVE-2004-1158

Published: 10/01/2005 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote malicious users to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

kde konqueror 2.2.1

kde konqueror 2.2.2

kde konqueror 3.0

kde konqueror 3.1.1

kde konqueror 3.1.2

kde konqueror 3.3

kde konqueror 3.3.1

kde konqueror 2.1.1

kde konqueror 2.1.2

kde konqueror 3.0.5b

kde konqueror 3.1

kde konqueror 3.2.2.6

kde konqueror 3.2.3

kde konqueror 3.0.3

kde konqueror 3.0.5

kde konqueror 3.1.5

kde konqueror 3.2.1

kde konqueror 3.0.1

kde konqueror 3.0.2

kde konqueror 3.1.3

kde konqueror 3.1.4

kde konqueror 3.3.2

redhat fedora core core_3.0

mandrakesoft mandrake linux 10.1

redhat fedora core core_2.0

mandrakesoft mandrake linux 10.0

Vendor Advisories

Synopsis kdelibs, kdebase security update Type/Severity Security Advisory: Important Topic Updated kdelib and kdebase packages that resolve several security issuesare now available Description The kdelibs packages include libraries for the K Desktop Environment Thekdebase packages include ...