CVE-2004-0904
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.01%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 8.01% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/firefox · mozilla/mozilla · mozilla/thunderbird · netscape/navigator · conectiva/linux · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/fedora core · redhat/linux · redhat/linux advanced workstation
- Source
- cve@mitre.org
References
- http://bugzilla.mozilla.org/show_bug.cgi?id=255067Vendor Advisory
- http://marc.info/?l=bugtraq&m=109698896104418&w=2
- http://marc.info/?l=bugtraq&m=109900315219363&w=2
- http://security.gentoo.org/glsa/glsa-200409-26.xml
- http://www.kb.cert.org/vuls/id/847200Third Party Advisory, US Government Resource
- http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3
- http://www.novell.com/linux/security/advisories/2004_36_mozilla.html
- http://www.securityfocus.com/bid/11171Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-261A.htmlUS Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17381
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10952
- http://bugzilla.mozilla.org/show_bug.cgi?id=255067Vendor Advisory
- http://marc.info/?l=bugtraq&m=109698896104418&w=2
- http://marc.info/?l=bugtraq&m=109900315219363&w=2
- http://security.gentoo.org/glsa/glsa-200409-26.xml
- http://www.kb.cert.org/vuls/id/847200Third Party Advisory, US Government Resource
- http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3
- http://www.novell.com/linux/security/advisories/2004_36_mozilla.html
- http://www.securityfocus.com/bid/11171Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA04-261A.htmlUS Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17381
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10952
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.