CVE Vulnerabilities

CVE-2004-1316

Published: Dec 29, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Heap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote attackers to cause a denial of service (application crash) via an NNTP URL (news:) with a trailing (backslash) character, which prevents a string from being NULL terminated.

Affected Software

NameVendorStart VersionEnd Version
MozillaMozilla**
MozillaMozilla1.3 (including)1.3 (including)
MozillaMozilla1.4 (including)1.4 (including)
MozillaMozilla1.4-alpha (including)1.4-alpha (including)
MozillaMozilla1.4.1 (including)1.4.1 (including)
MozillaMozilla1.5 (including)1.5 (including)
MozillaMozilla1.5-alpha (including)1.5-alpha (including)
MozillaMozilla1.5-rc1 (including)1.5-rc1 (including)
MozillaMozilla1.5-rc2 (including)1.5-rc2 (including)
MozillaMozilla1.5.1 (including)1.5.1 (including)
MozillaMozilla1.6 (including)1.6 (including)
MozillaMozilla1.6-alpha (including)1.6-alpha (including)
MozillaMozilla1.6-beta (including)1.6-beta (including)
MozillaMozilla1.7 (including)1.7 (including)
MozillaMozilla1.7-alpha (including)1.7-alpha (including)
MozillaMozilla1.7-beta (including)1.7-beta (including)
MozillaMozilla1.7-rc1 (including)1.7-rc1 (including)
MozillaMozilla1.7-rc2 (including)1.7-rc2 (including)
MozillaMozilla1.7-rc3 (including)1.7-rc3 (including)
MozillaMozilla1.7.1 (including)1.7.1 (including)
MozillaMozilla1.7.2 (including)1.7.2 (including)
MozillaMozilla1.7.3 (including)1.7.3 (including)
MozillaUbuntuedgy*

References