CVE-2004-0908

Mozilla Firefox 1.7.3 & Thunderbird 0.8 - Unauthenticated Clipboard Data Access

Title source: llm
STIX 2.1

Description

Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript code to read and write to the clipboard, and possibly obtain sensitive information, via script-generated events such as Ctrl-Ins.

References (11)

Core 11
Core References
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11179
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/460528
Mailing List vendor-advisory x_refsource_fedora
http://marc.info/?l=bugtraq&m=109900315219363&w=2
Exploit, Patch x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=257523
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9745
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200409-26.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17376
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=109698896104418&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/12526

Scores

EPSS 0.0245
EPSS Percentile 82.6%

Details

Status published
Products (37)
mozilla/mozilla 0.8
mozilla/mozilla 0.9.2
mozilla/mozilla 0.9.2.1
mozilla/mozilla 0.9.3
mozilla/mozilla 0.9.4
mozilla/mozilla 0.9.4.1
mozilla/mozilla 0.9.5
mozilla/mozilla 0.9.6
mozilla/mozilla 0.9.7
mozilla/mozilla 0.9.8
... and 27 more
Published Dec 31, 2004
Tracked Since Feb 18, 2026