CVE-2004-1314: High severity Safari vulnerability
Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability, a different vulnerability than CVE-2004-1122.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1314?
CVE-2004-1314 is considered a high severity vulnerability due to its potential to allow website spoofing.
How do I fix CVE-2004-1314?
To fix CVE-2004-1314, upgrade to the latest version of Safari that addresses this vulnerability.
Which versions of Safari are affected by CVE-2004-1314?
CVE-2004-1314 affects Safari versions 1.0 through 1.2.3.
What is the primary threat posed by CVE-2004-1314?
The primary threat of CVE-2004-1314 is the ability for attackers to spoof trusted websites through window injection.
Can CVE-2004-1314 be exploited remotely?
Yes, CVE-2004-1314 can be exploited remotely by attackers injecting content from one window into another.