CVE-2004-1489
 
Severity Score
2.6
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2004-12-31 CVE Published
- 2005-02-17 CVE Reserved
- 2024-01-25 EPSS Updated
- 2024-08-08 CVE Updated
- 2024-08-08 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-668: Exposure of Resource to Wrong Sphere
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.opera.com/linux/changelogs/754u1 | Broken Link |
URL | Date | SRC |
---|---|---|
http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029044.html | 2024-08-08 |
URL | Date | SRC |
---|---|---|
http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml | 2022-02-28 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Opera Search vendor "Opera" | Opera Browser Search vendor "Opera" for product "Opera Browser" | <= 7.54 Search vendor "Opera" for product "Opera Browser" and version " <= 7.54" | - |
Affected
|