CVE-2004-1050
Last modified
CVE-2004-1050 is a vulnerability of currently unknown severity. Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability.". EPSS estimates a 67.06% chance of exploitation in the next 30 days.
Description
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Avaya | Ip600 Media Servers | All versions | — |
| Avaya | Ip600 Media Servers | r6 | — |
| Avaya | Ip600 Media Servers | r7 | — |
| Avaya | Ip600 Media Servers | r8 | — |
| Avaya | Ip600 Media Servers | r9 | — |
| Avaya | Ip600 Media Servers | r10 | — |
| Avaya | Ip600 Media Servers | r11 | — |
| Avaya | Ip600 Media Servers | r12 | — |
| Microsoft | Ie | 6.0 | Sp1 |
| Microsoft | Internet Explorer | 6.0 | — |
| Avaya | Definity One Media Server | All versions | — |
| Avaya | Definity One Media Server | r6 | — |
| Avaya | Definity One Media Server | r7 | — |
| Avaya | Definity One Media Server | r8 | — |
| Avaya | Definity One Media Server | r9 | — |
| Avaya | Definity One Media Server | r10 | — |
| Avaya | Definity One Media Server | r11 | — |
| Avaya | Definity One Media Server | r12 | — |
| Avaya | S3400 | All versions | — |
| Avaya | S8100 | All versions | — |
| Avaya | S8100 | r6 | — |
| Avaya | S8100 | r7 | — |
| Avaya | S8100 | r8 | — |
| Avaya | S8100 | r9 | — |
| Avaya | S8100 | r10 | — |
| Avaya | S8100 | r11 | — |
| Avaya | S8100 | r12 | — |
| Avaya | Modular Messaging Message Storage Server | s3400 | — |
References
- http://www.kb.cert.org/vuls/id/842160Third Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-315A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-336A.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/842160Third Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-315A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-336A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1050?
How severe is CVE-2004-1050?
How do I fix CVE-2004-1050?
Are you affected by CVE-2004-1050?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
