Opera 7.50 and earlier allows remote web sites to provide a "Shortcut Icon" (favicon) that is wider than expected, which could allow the web sites to spoof a trusted domain and facilitate phishing attacks using a wide icon and extra spaces.
References
Configurations
History
20 Nov 2024, 23:48
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022263.html - Third Party Advisory | |
References | () http://marc.info/?l=bugtraq&m=108627581717738&w=2 - Mailing List | |
References | () http://osvdb.org/6590 - Broken Link | |
References | () http://secunia.com/advisories/11762 - Broken Link | |
References | () http://security.greymagic.com/security/advisories/gm007-op/ - Broken Link | |
References | () http://www.opera.com/linux/changelogs/751/index.dml - Broken Link | |
References | () http://www.securityfocus.com/bid/10452 - Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/16307 - Third Party Advisory, VDB Entry |
28 Feb 2022, 17:28
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:opera_software:opera_web_browser:7.50:*:*:*:*:*:*:* |
cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:* |
References | (CONFIRM) http://www.opera.com/linux/changelogs/751/index.dml - Broken Link | |
References | (FULLDISC) http://lists.grok.org.uk/pipermail/full-disclosure/2004-June/022263.html - Third Party Advisory | |
References | (MISC) http://security.greymagic.com/security/advisories/gm007-op/ - Broken Link | |
References | (BUGTRAQ) http://marc.info/?l=bugtraq&m=108627581717738&w=2 - Mailing List | |
References | (OSVDB) http://osvdb.org/6590 - Broken Link | |
References | (SECUNIA) http://secunia.com/advisories/11762 - Broken Link | |
References | (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/16307 - Third Party Advisory, VDB Entry | |
References | (BID) http://www.securityfocus.com/bid/10452 - Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory |
Information
Published : 2004-08-06 04:00
Updated : 2024-11-20 23:48
NVD link : CVE-2004-0537
Mitre link : CVE-2004-0537
CVE.ORG link : CVE-2004-0537
JSON object : View
Products Affected
opera
- opera_browser
CWE