CVE-2004-1614
Last modified
CVE-2004-1614 is a vulnerability of currently unknown severity. Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an "unusual combination of visual elements," including several large MARQUEE tags with large height parameters, as demonstrated by mangleme.. EPSS estimates a 1.50% chance of exploitation in the next 30 days.
Description
Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an "unusual combination of visual elements," including several large MARQUEE tags with large height parameters, as demonstrated by mangleme.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Mozilla | Mozilla | 1.0 | — |
| Mozilla | Mozilla | 1.0.1 | — |
| Mozilla | Mozilla | 1.0.2 | — |
| Mozilla | Mozilla | 1.1 | — |
| Mozilla | Mozilla | 1.2 | — |
| Mozilla | Mozilla | 1.2.1 | — |
| Mozilla | Mozilla | 1.3 | — |
| Mozilla | Mozilla | 1.3.1 | — |
| Mozilla | Mozilla | 1.4 | — |
| Mozilla | Mozilla | 1.4.1 | — |
| Mozilla | Mozilla | 1.4.2 | — |
| Mozilla | Mozilla | 1.5 | — |
| Mozilla | Mozilla | 1.6 | — |
| Mozilla | Mozilla | 1.7 | — |
| Mozilla | Mozilla | 1.7.1 | — |
| Mozilla | Mozilla | 1.7.2 | — |
| Mozilla | Mozilla | 1.7.3 | — |
| Mozilla | Mozilla | 1.8 | Alpha2 |
References
- http://lcamtuf.coredump.cx/mangleme/gallery/Vendor Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027709.htmlExploit, Vendor Advisory
- http://www.securityfocus.com/bid/11440Exploit, Vendor Advisory
- http://lcamtuf.coredump.cx/mangleme/gallery/Vendor Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/027709.htmlExploit, Vendor Advisory
- http://www.securityfocus.com/bid/11440Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1614?
How severe is CVE-2004-1614?
How do I fix CVE-2004-1614?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-1608SQL injection vulnerability in SalesLogix 6.1 allows remote …
- CVE-2004-1609SalesLogix 6.1 includes usernames, passwords, and other sens…
- CVE-2004-1610SalesLogix 6.1 uses client-specified pathnames for writing c…
- CVE-2004-1611SalesLogix 6.1 does not verify if a user is authenticated be…
- CVE-2004-1612Directory traversal vulnerability in SalesLogix 6.1 allows r…
- CVE-2004-1613Mozilla allows remote attackers to cause a denial of service…
- CVE-2004-1615Opera allows remote attackers to cause a denial of service (…
- CVE-2004-1616Links allows remote attackers to cause a denial of service (…
- CVE-2004-1617Lynx, lynx-ssl, and lynx-cur before 2.8.6dev.8 allow remote …
- CVE-2004-1618Vypress Tonecast 1.3 and earlier allows remote attackers to …
- CVE-2004-1619Buffer overflow in Privateer's Bounty: Age of Sail II allows…
- CVE-2004-1620CRLF injection vulnerability in Serendipity before 0.7rc1 al…
Are you affected by CVE-2004-1614?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
