Vulnerability record · CVE-2004-2491 · published 31 December 2004
CVE-2004-2491: Opera browser race condition vulnerability
Opera · Opera Browser
A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing attacks.
Description
A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing attacks.
AV:N/AC:H/Au:N/C:N/I:P/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://archives.neohapsis.com/archives/fulldisclosure/2004-07/1056.html | Broken LinkExploit |
| http://secunia.com/advisories/12162 | Broken LinkPatch |
| http://www.opera.com/windows/changelogs/754/ | Broken LinkPatch |
| http://www.osvdb.org/8317 | Broken LinkExploit |
| http://www.securityfocus.com/bid/10810 | Broken LinkExploitPatchThird Party AdvisoryVDB Entry |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/16816 | Third Party AdvisoryVDB Entry |
| http://archives.neohapsis.com/archives/fulldisclosure/2004-07/1056.html | Broken LinkExploit |
| http://secunia.com/advisories/12162 | Broken LinkPatch |
| http://www.opera.com/windows/changelogs/754/ | Broken LinkPatch |
| http://www.osvdb.org/8317 | Broken LinkExploit |
| http://www.securityfocus.com/bid/10810 | Broken LinkExploitPatchThird Party AdvisoryVDB Entry |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/16816 | Third Party AdvisoryVDB Entry |
Track CVE-2004-2491 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-2491), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.