CVE-2004-0909
Mozilla Firefox and Thunderbird - Privilege Escalation via Signed Script Dialog Spoofing
Title source: llmDescription
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 may allow remote attackers to trick users into performing unexpected actions, including installing software, via signed scripts that request enhanced abilities using the enablePrivilege parameter, then modify the meaning of certain security-relevant dialog messages.
References (8)
Core 8
Core References
Vendor Advisory vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2004_36_mozilla.html
Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/113192
Various Sources x_refsource_confirm
http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17377
Exploit x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=253942
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200409-26.xml
Mailing List vendor-advisory
x_refsource_hp
http://marc.info/?l=bugtraq&m=109698896104418&w=2
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/12526
Scores
EPSS
0.0171
EPSS Percentile
74.8%
Details
Status
published
Products (37)
mozilla/mozilla
0.8
mozilla/mozilla
0.9.2
mozilla/mozilla
0.9.2.1
mozilla/mozilla
0.9.3
mozilla/mozilla
0.9.4
mozilla/mozilla
0.9.4.1
mozilla/mozilla
0.9.5
mozilla/mozilla
0.9.6
mozilla/mozilla
0.9.7
mozilla/mozilla
0.9.8
... and 27 more
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026