CVE-2004-2491: Race Condition
A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing attacks.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2491?
CVE-2004-2491 is classified as a moderate severity vulnerability due to its potential to facilitate phishing attacks.
How do I fix CVE-2004-2491?
To fix CVE-2004-2491, users should update the Opera web browser to version 7.54 or later.
Which versions of Opera are affected by CVE-2004-2491?
CVE-2004-2491 affects Opera web browser versions up to and including 7.53.
What type of attack does CVE-2004-2491 enable?
CVE-2004-2491 enables phishing attacks by allowing attackers to spoof the URL in the address bar.
What causes the vulnerability in CVE-2004-2491?
CVE-2004-2491 is caused by a race condition in Opera that allows premature filling of the address bar.