SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-1753

The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and…

LOW 2.6EPSS 1.60%

Does this matter?

Lower severity and a low EPSS score (1.60%). Track it; it rarely justifies an emergency change on its own.

Description

The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs.

CVSS 2.0
2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
EPSS
1.60% probability · 74th percentile
CISA KEV
Not listed
Affected
mozilla/firefox · mozilla/mozilla · netscape/navigator
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.