← Back

CVE-2004-0904

nvd nist
Published: Dec 31, 2004Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.

Affected (38)

Show all products
1 product
Linux
3 products
Firefox
Mozilla
Thunderbird
1 product
Navigator
5 products
Enterprise Linux
Enterprise Linux Desktop
Fedora Core
Linux
Linux Advanced Workstation
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Conectiva
Version 10.0
Version 9.0
Mozilla
Version 0.8
Version 0.9.1
Version 0.9.2
Version 0.9.3
Version 0.9
Version 0.9 rc
Mozilla
Version 1.7.1
Version 1.7.2
Version 1.7
Version 1.7 rc3
Mozilla
Version 0.6
Version 0.7.1
Version 0.7.2
Version 0.7.3
Version 0.7
Netscape
Version 7.0.2
Version 7.0
Version 7.1
Version 7.2
Configuration B
17 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 2.1
Version 2.1
Version 2.1
Version 2.1
Version 2.1
Version 2.1
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version core_1.0
Redhat
Version 7.3
Version 7.3
Version 7.3
Version 9.0
Redhat
Version 2.1
Version 2.1

References (22)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.