← All CVEs

CVE-2004-0902

high · 10

Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII hostname.

10
CVSS
10.1%
EPSS (exploit prob.)
95th
EPSS percentile
2005-01-27
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
mozillamozilla1.7
mozillamozilla1.7.1
mozillamozilla1.7.2
mozillathunderbird0.7
mozillathunderbird0.7.1
mozillathunderbird0.7.2
mozillathunderbird0.7.3
conectivalinux9.0
conectivalinux10.0
redhatenterprise_linux2.1
redhatenterprise_linux2.1
redhatenterprise_linux2.1
redhatenterprise_linux2.1
redhatenterprise_linux2.1
redhatenterprise_linux2.1
redhatenterprise_linux3.0
redhatenterprise_linux3.0
redhatenterprise_linux3.0
redhatenterprise_linux_desktop3.0
redhatfedora_corecore_1.0
redhatlinux7.3
redhatlinux7.3
redhatlinux7.3
redhatlinux9.0
redhatlinux_advanced_workstation2.1
redhatlinux_advanced_workstation2.1
susesuse_linux1.0
susesuse_linux8
susesuse_linux8.1
susesuse_linux8.2
susesuse_linux9.0
susesuse_linux9.0
susesuse_linux9.0
susesuse_linux9.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-0902