← Back

CVE-2004-0903

nvd nist
Published: Jan 27, 2005Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.

Affected (34)

Show all products
1 product
Linux
2 products
Mozilla
Thunderbird
5 products
Enterprise Linux
Enterprise Linux Desktop
Fedora Core
Linux
Linux Advanced Workstation
1 product
Suse Linux
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Conectiva
Version 10.0
Version 9.0
Mozilla
Version 1.7.1
Version 1.7.2
Version 1.7
Mozilla
Version 0.7.1
Version 0.7.2
Version 0.7.3
Version 0.7
Configuration B
25 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 2.1
Version 2.1
Version 2.1
Version 2.1
Version 2.1
Version 2.1
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version core_1.0
Redhat
Version 7.3
Version 7.3
Version 7.3
Version 9.0
Redhat
Version 2.1
Version 2.1
Suse
Version 1.0
Version 8.1
Version 8.2
Version 8
Version 9.0
Version 9.0
Version 9.0
Version 9.1

References (22)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.