← Back

CVE-2004-1451

nvd nist
Published: Dec 31, 2004Modified: Apr 16, 2026

JSON object

Loading...
2.6
Vector
AV:N/AC:H/Au:N/C:N/I:P/A:N
Exploitability: 4.9 / Impact: 2.9
Source: NVD

Description

Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrusted sites and facilitate phishing attacks.

Affected (35)

Products: Mozilla: Mozilla
1 product
Mozilla
Configuration A
35 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 0.8
Version 0.9.2.1
Version 0.9.2
Version 0.9.35
Version 0.9.3
Version 0.9.4.1
Version 0.9.48
Version 0.9.4
Version 0.9.5
Version 0.9.6
Version 0.9.7
Version 0.9.8
Version 0.9.9
Version 1.0.1
Version 1.0.2
Version 1.0
Version 1.0 rc1
Version 1.0 rc2
Version 1.1
Version 1.1 alpha
Version 1.1 beta
Version 1.2.1
Version 1.2
Version 1.2 alpha
Version 1.2 beta
Version 1.3.1
Version 1.3
Version 1.4.1
Version 1.4.2
Version 1.4.4
Version 1.4
Version 1.4 alpha
Version 1.4 beta
Version 1.5.1
Version 1.5

References (6)

Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.