CVE-2004-0902

5 documents5 sources
Severity
10.0CRITICAL
EPSS
27.9%
top 3.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 27
Latest updateApr 29

Description

Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII hostname.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages8 packages

NVDmozilla/thunderbird4 versions+3
NVDmozilla/mozilla1.7, 1.7.1, 1.7.2+2
NVDredhat/linux7.3, 9.0+1
NVDconectiva/linux10.0, 9.0+1
NVDsuse/suse_linux6 versions+5

Also affects: Enterprise Linux 2.1, 3.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-53rc-xfx7-6qmc: Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 12022-04-29
CVEList
CVE-2004-0902: Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 12004-09-24

📋Vendor Advisories

1
Red Hat
security flaw2004-09-04

💬Community

1
Bugzilla
CVE-2004-0902 security flaw2018-08-16
CVE-2004-0902 (CRITICAL CVSS 10) | Multiple heap-based buffer overflow | cvebase.io