CVE-2004-0909
Summary
| CVE | CVE-2004-0909 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 may allow remote attackers to trick users into performing unexpected actions, including installing software, via signed scripts that request enhanced abilities using the enablePrivilege parameter, then modify the meaning of certain security-relevant dialog messages. |
Risk And Classification
Primary CVSS: v2.0 5.1 from [email protected]
AV:N/AC:H/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:H/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Mozilla | 0.8 | All | All | All |
| Application | Mozilla | Mozilla | 0.9.2 | All | All | All |
| Application | Mozilla | Mozilla | 0.9.2.1 | All | All | All |
| Application | Mozilla | Mozilla | 0.9.3 | All | All | All |
| Application | Mozilla | Mozilla | 0.9.35 | All | All | All |
| Application | Mozilla | Mozilla | 0.9.4 | All | All | All |
| Application | Mozilla | Mozilla | 0.9.4.1 | All | All | All |
| Application | Mozilla | Mozilla | 0.9.48 | All | All | All |
| Application | Mozilla | Mozilla | 0.9.5 | All | All | All |
| Application | Mozilla | Mozilla | 0.9.6 | All | All | All |
| Application | Mozilla | Mozilla | 0.9.7 | All | All | All |
| Application | Mozilla | Mozilla | 0.9.8 | All | All | All |
| Application | Mozilla | Mozilla | 0.9.9 | All | All | All |
| Application | Mozilla | Mozilla | 1.0 | All | All | All |
| Application | Mozilla | Mozilla | 1.0 | rc1 | All | All |
| Application | Mozilla | Mozilla | 1.0 | rc2 | All | All |
| Application | Mozilla | Mozilla | 1.0.1 | All | All | All |
| Application | Mozilla | Mozilla | 1.0.2 | All | All | All |
| Application | Mozilla | Mozilla | 1.1 | All | All | All |
| Application | Mozilla | Mozilla | 1.1 | alpha | All | All |
| Application | Mozilla | Mozilla | 1.1 | beta | All | All |
| Application | Mozilla | Mozilla | 1.2 | All | All | All |
| Application | Mozilla | Mozilla | 1.2 | alpha | All | All |
| Application | Mozilla | Mozilla | 1.2 | beta | All | All |
| Application | Mozilla | Mozilla | 1.2.1 | All | All | All |
| Application | Mozilla | Mozilla | 1.3 | All | All | All |
| Application | Mozilla | Mozilla | 1.3.1 | All | All | All |
| Application | Mozilla | Mozilla | 1.4 | All | All | All |
| Application | Mozilla | Mozilla | 1.4 | alpha | All | All |
| Application | Mozilla | Mozilla | 1.4 | beta | All | All |
| Application | Mozilla | Mozilla | 1.4.1 | All | All | All |
| Application | Mozilla | Mozilla | 1.4.2 | All | All | All |
| Application | Mozilla | Mozilla | 1.4.4 | All | All | All |
| Application | Mozilla | Mozilla | 1.5 | All | All | All |
| Application | Mozilla | Mozilla | 1.5.1 | All | All | All |
| Application | Mozilla | Mozilla | 1.6 | All | All | All |
| Application | Mozilla | Mozilla | 1.7 | All | All | All |
| Application | Mozilla | Mozilla | 1.7 | alpha | All | All |
| Application | Mozilla | Mozilla | 1.7 | beta | All | All |
| Application | Mozilla | Mozilla | 1.7 | rc1 | All | All |
| Application | Mozilla | Mozilla | 1.7 | rc2 | All | All |
| Application | Mozilla | Mozilla | 1.7 | rc3 | All | All |
| Application | Mozilla | Mozilla | 1.7.1 | All | All | All |
| Application | Mozilla | Mozilla | 1.7.2 | All | All | All |
| Application | Mozilla | Thunderbird | 0.1 | All | All | All |
| Application | Mozilla | Thunderbird | 0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 0.3 | All | All | All |
| Application | Mozilla | Thunderbird | 0.4 | All | All | All |
| Application | Mozilla | Thunderbird | 0.5 | All | All | All |
| Application | Mozilla | Thunderbird | 0.6 | All | All | All |
| Application | Mozilla | Thunderbird | 0.7 | All | All | All |
| Application | Mozilla | Thunderbird | 0.7.1 | All | All | All |
| Application | Mozilla | Thunderbird | 0.7.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| '[security bulletin]SSRT4826 rev.0 Mozilla Application Suite for HP Tru64 UNIX Multiple Potential Sec' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | Vendor Advisory |
| Mozilla Security Advisory | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | |
| Secunia - Advisories - Mozilla Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo Linux Documentation -- Mozilla, Firefox, Thunderbird, Epiphany: New releases fix vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| US-CERT Vulnerability Note VU#113192 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| 253942 – enablePrivilege parameter can change the meaning of the dialog | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.