cbcvebase.
CVE-2004-1050
published 2004-12-31

CVE-2004-1050: Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME…

critical10CVSS 3.1
AVNACLAuNCCICAC
EXPLOIT
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."

Affected

24 ranges
VendorProductVersion rangeFixed in
avayadefinity_one_media_server
avayadefinity_one_media_server
avayadefinity_one_media_server
avayadefinity_one_media_server
avayadefinity_one_media_server
avayadefinity_one_media_server
avayadefinity_one_media_server
avayaip600_media_servers
avayaip600_media_servers
avayaip600_media_servers
avayaip600_media_servers
avayaip600_media_servers
avayaip600_media_servers
avayaip600_media_servers
avayamodular_messaging_message_storage_server
avayas8100
avayas8100
avayas8100
avayas8100
avayas8100
avayas8100
avayas8100
microsoftie
microsoftinternet_explorer

CVSS provenance

nvd10.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL