CVE-2004-0537

Opera 7.50 and earlier allows remote web sites to provide a "Shortcut Icon" (favicon) that is wider than expected, which could allow the web sites to spoof a trusted domain and facilitate phishing attacks using a wide icon and extra spaces.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:48

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022263.html - Third Party Advisory () http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022263.html - Third Party Advisory
References () http://marc.info/?l=bugtraq&m=108627581717738&w=2 - Mailing List () http://marc.info/?l=bugtraq&m=108627581717738&w=2 - Mailing List
References () http://osvdb.org/6590 - Broken Link () http://osvdb.org/6590 - Broken Link
References () http://secunia.com/advisories/11762 - Broken Link () http://secunia.com/advisories/11762 - Broken Link
References () http://security.greymagic.com/security/advisories/gm007-op/ - Broken Link () http://security.greymagic.com/security/advisories/gm007-op/ - Broken Link
References () http://www.opera.com/linux/changelogs/751/index.dml - Broken Link () http://www.opera.com/linux/changelogs/751/index.dml - Broken Link
References () http://www.securityfocus.com/bid/10452 - Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory () http://www.securityfocus.com/bid/10452 - Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/16307 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/16307 - Third Party Advisory, VDB Entry

28 Feb 2022, 17:28

Type Values Removed Values Added
CWE NVD-CWE-Other NVD-CWE-noinfo
CPE cpe:2.3:a:opera_software:opera_web_browser:7.23:*:*:*:*:*:*:*
cpe:2.3:a:opera_software:opera_web_browser:7.50:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:*
References (CONFIRM) http://www.opera.com/linux/changelogs/751/index.dml - (CONFIRM) http://www.opera.com/linux/changelogs/751/index.dml - Broken Link
References (FULLDISC) http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022263.html - (FULLDISC) http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022263.html - Third Party Advisory
References (MISC) http://security.greymagic.com/security/advisories/gm007-op/ - (MISC) http://security.greymagic.com/security/advisories/gm007-op/ - Broken Link
References (BUGTRAQ) http://marc.info/?l=bugtraq&m=108627581717738&w=2 - (BUGTRAQ) http://marc.info/?l=bugtraq&m=108627581717738&w=2 - Mailing List
References (OSVDB) http://osvdb.org/6590 - (OSVDB) http://osvdb.org/6590 - Broken Link
References (SECUNIA) http://secunia.com/advisories/11762 - (SECUNIA) http://secunia.com/advisories/11762 - Broken Link
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/16307 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/16307 - Third Party Advisory, VDB Entry
References (BID) http://www.securityfocus.com/bid/10452 - Patch, Vendor Advisory (BID) http://www.securityfocus.com/bid/10452 - Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory

Information

Published : 2004-08-06 04:00

Updated : 2024-11-20 23:48


NVD link : CVE-2004-0537

Mitre link : CVE-2004-0537

CVE.ORG link : CVE-2004-0537


JSON object : View

Products Affected

opera

  • opera_browser