VDB
CVE-2004-1050
CVE-2004-1050
PUBLISHED
CVSS 10 CRITICAL
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."
EPSS 81.51% · 99.2th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
81.51%
99.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| avaya | definity_one_media_server | *, *, * |
| avaya | modular_messaging_message_storage_server | s3400, s3400, * |
| avaya | s8100 | *, r6, r9 |
| n/a | n/a | n/a, n/a |
| avaya | s3400 | |
| avaya | ip600_media_servers | *, r9, r12 |
| microsoft | internet_explorer | 6.0, 6.0, 6.0 |
| microsoft | ie | 6.0, 6.0, 6.0 |
Timeline
- Nov 18, 2004 CVE Published
- Dec 1, 2004 VulnCheck KEV Exploitation
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- VU#842160 third-party-advisory
- 20041023 python does mangleme (with IE bugs!) mailing-list
- MS04-040 vendor-advisory
- 20041102 MSIE <IFRAME> and <FRAME> tag NAME property bufferoverflow PoC mailing-list
- 11515 vdb
- oval:org.mitre.oval:def:1294 vdb
- 20041025 python does mangleme (with IE bugs!) mailing-list
- TA04-315A third-party-advisory
- ie-iframe-src-name-bo(17889) vdb
- 12959 third-party-advisory
- 20041024 python does mangleme (with IE bugs!) mailing-list
- TA04-336A third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2004-1050 advisory
- http://secunia.com/advisories/12959 url