CVE Vulnerabilities

CVE-2004-0904

Published: Dec 31, 2004 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 0.8 (including) 0.8 (including)
Firefox Mozilla 0.9 (including) 0.9 (including)
Firefox Mozilla 0.9-rc (including) 0.9-rc (including)
Firefox Mozilla 0.9.1 (including) 0.9.1 (including)
Firefox Mozilla 0.9.2 (including) 0.9.2 (including)
Firefox Mozilla 0.9.3 (including) 0.9.3 (including)
Mozilla Mozilla 1.7 (including) 1.7 (including)
Mozilla Mozilla 1.7-rc3 (including) 1.7-rc3 (including)
Mozilla Mozilla 1.7.1 (including) 1.7.1 (including)
Mozilla Mozilla 1.7.2 (including) 1.7.2 (including)
Thunderbird Mozilla 0.6 (including) 0.6 (including)
Thunderbird Mozilla 0.7 (including) 0.7 (including)
Thunderbird Mozilla 0.7.1 (including) 0.7.1 (including)
Thunderbird Mozilla 0.7.2 (including) 0.7.2 (including)
Thunderbird Mozilla 0.7.3 (including) 0.7.3 (including)
Navigator Netscape 7.0 (including) 7.0 (including)
Navigator Netscape 7.0.2 (including) 7.0.2 (including)
Navigator Netscape 7.1 (including) 7.1 (including)
Navigator Netscape 7.2 (including) 7.2 (including)
Linux Conectiva 9.0 (including) 9.0 (including)
Linux Conectiva 10.0 (including) 10.0 (including)
Red Hat Enterprise Linux 2.1 RedHat galeon *
Red Hat Enterprise Linux 2.1 RedHat mozilla *
Red Hat Enterprise Linux 3 RedHat mozilla *

References