CVE-2004-0978
high · 10Heap-based buffer overflow in the Hrtbeat.ocx (Heartbeat) ActiveX control for Internet Explorer 5.01 through 6, when users who visit online gaming sites that are associated with MSN, allows remote attackers to execute arbitrary code via the SetupData parameter.
10
CVSS
38.3%
EPSS (exploit prob.)
98th
EPSS percentile
2005-02-09
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-787
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | internet_explorer | 5.01 |
| microsoft | internet_explorer | 5.01 |
| microsoft | windows_2000 | all versions |
| microsoft | windows_2000 | all versions |
| microsoft | internet_explorer | 5.5 |
| microsoft | windows_me | all versions |
| microsoft | internet_explorer | 6 |
| microsoft | windows_server_2003 | all versions |
| microsoft | windows_server_2003 | all versions |
| microsoft | windows_xp | all versions |
| microsoft | windows_xp | all versions |
| microsoft | windows_xp | all versions |
| microsoft | windows_xp | all versions |
| microsoft | internet_explorer | 6 |
| microsoft | windows_2000 | all versions |
| microsoft | windows_2000 | all versions |
| microsoft | windows_98se | all versions |
| microsoft | windows_me | all versions |
| microsoft | windows_nt | 4.0 |
| microsoft | windows_nt | 4.0 |
| microsoft | windows_xp | all versions |
| microsoft | windows_xp | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://marc.info/?l=bugtraq&m=110616221411579&w=2
- http://www.kb.cert.org/vuls/id/673134
- http://www.ngssoftware.com/advisories/heartbeatfull.txt
- http://www.securityfocus.com/bid/11367
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17714
- http://marc.info/?l=bugtraq&m=110616221411579&w=2
- http://www.kb.cert.org/vuls/id/673134
- http://www.ngssoftware.com/advisories/heartbeatfull.txt
- http://www.securityfocus.com/bid/11367
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17714
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2004-0978