CVE-2004-1050
high · 10Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."
10
CVSS
67.1%
EPSS (exploit prob.)
99th
EPSS percentile
2004-12-31
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| avaya | ip600_media_servers | all versions |
| avaya | ip600_media_servers | r6 |
| avaya | ip600_media_servers | r7 |
| avaya | ip600_media_servers | r8 |
| avaya | ip600_media_servers | r9 |
| avaya | ip600_media_servers | r10 |
| avaya | ip600_media_servers | r11 |
| avaya | ip600_media_servers | r12 |
| microsoft | ie | 6.0 |
| microsoft | internet_explorer | 6.0 |
| avaya | definity_one_media_server | all versions |
| avaya | definity_one_media_server | r6 |
| avaya | definity_one_media_server | r7 |
| avaya | definity_one_media_server | r8 |
| avaya | definity_one_media_server | r9 |
| avaya | definity_one_media_server | r10 |
| avaya | definity_one_media_server | r11 |
| avaya | definity_one_media_server | r12 |
| avaya | s3400 | all versions |
| avaya | s8100 | all versions |
| avaya | s8100 | r6 |
| avaya | s8100 | r7 |
| avaya | s8100 | r8 |
| avaya | s8100 | r9 |
| avaya | s8100 | r10 |
| avaya | s8100 | r11 |
| avaya | s8100 | r12 |
| avaya | modular_messaging_message_storage_server | s3400 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028009.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028035.html
- http://marc.info/?l=bugtraq&m=109942758911846&w=2
- http://secunia.com/advisories/12959/
- http://www.kb.cert.org/vuls/id/842160
- http://www.securityfocus.com/archive/1/379261
- http://www.securityfocus.com/bid/11515
- http://www.us-cert.gov/cas/techalerts/TA04-315A.html
- http://www.us-cert.gov/cas/techalerts/TA04-336A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-040
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17889
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1294
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028009.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028035.html
- http://marc.info/?l=bugtraq&m=109942758911846&w=2
- http://secunia.com/advisories/12959/
- http://www.kb.cert.org/vuls/id/842160
- http://www.securityfocus.com/archive/1/379261
- http://www.securityfocus.com/bid/11515
- http://www.us-cert.gov/cas/techalerts/TA04-315A.html
- http://www.us-cert.gov/cas/techalerts/TA04-336A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-040
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17889
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1294
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2004-1050