CVE-2004-1613

5 documents5 sources
Severity
5.0MEDIUM
EPSS
1.4%
top 19.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 18
Latest updateApr 29

Description

Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages6 packages

NVDmozilla/mozilla19 versions+18
NVDsgi/propack3.0
NVDredhat/linux7.3, 9.0+1
NVDredhat/fedora_corecore_1.0, core_2.0+1

Also affects: Enterprise Linux 2.1, 3.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pqwg-424h-mwmq: Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a2022-04-29
CVEList
CVE-2004-1613: Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a2005-02-20

📋Vendor Advisories

1
Red Hat
security flaw2004-10-18

💬Community

1
Bugzilla
CVE-2004-1613 security flaw2018-08-16
CVE-2004-1613 (MEDIUM CVSS 5) | Mozilla allows remote attackers to | cvebase.io