Lucene search

K
cveMitreCVE-2004-0903
HistoryJan 27, 2005 - 5:00 a.m.

CVE-2004-0903

2005-01-2705:00:00
mitre
web.nvd.nist.gov
40
cve
2004
0903
stack-based buffer overflow
nsvcardobj.cpp
mozilla firefox
thunderbird
remote code execution
vcard attachments

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.116

Percentile

95.3%

Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.

Affected configurations

Nvd
Node
mozillamozillaMatch1.7
OR
mozillamozillaMatch1.7.1
OR
mozillamozillaMatch1.7.2
OR
mozillathunderbirdMatch0.7
OR
mozillathunderbirdMatch0.7.1
OR
mozillathunderbirdMatch0.7.2
OR
mozillathunderbirdMatch0.7.3
OR
conectivalinuxMatch9.0
OR
conectivalinuxMatch10.0
Node
redhatenterprise_linuxMatch2.1advanced_server
OR
redhatenterprise_linuxMatch2.1advanced_server_ia64
OR
redhatenterprise_linuxMatch2.1enterprise_server
OR
redhatenterprise_linuxMatch2.1enterprise_server_ia64
OR
redhatenterprise_linuxMatch2.1workstation
OR
redhatenterprise_linuxMatch2.1workstation_ia64
OR
redhatenterprise_linuxMatch3.0advanced_server
OR
redhatenterprise_linuxMatch3.0enterprise_server
OR
redhatenterprise_linuxMatch3.0workstation_server
OR
redhatenterprise_linux_desktopMatch3.0
OR
redhatfedora_coreMatchcore_1.0
OR
redhatlinuxMatch7.3
OR
redhatlinuxMatch7.3i386
OR
redhatlinuxMatch7.3i686
OR
redhatlinuxMatch9.0i386
OR
redhatlinux_advanced_workstationMatch2.1ia64
OR
redhatlinux_advanced_workstationMatch2.1itanium_processor
OR
susesuse_linuxMatch1.0desktop
OR
susesuse_linuxMatch8enterprise_server
OR
susesuse_linuxMatch8.1
OR
susesuse_linuxMatch8.2
OR
susesuse_linuxMatch9.0
OR
susesuse_linuxMatch9.0enterprise_server
OR
susesuse_linuxMatch9.0x86_64
OR
susesuse_linuxMatch9.1
VendorProductVersionCPE
mozillamozilla1.7cpe:2.3:a:mozilla:mozilla:1.7:*:*:*:*:*:*:*
mozillamozilla1.7.1cpe:2.3:a:mozilla:mozilla:1.7.1:*:*:*:*:*:*:*
mozillamozilla1.7.2cpe:2.3:a:mozilla:mozilla:1.7.2:*:*:*:*:*:*:*
mozillathunderbird0.7cpe:2.3:a:mozilla:thunderbird:0.7:*:*:*:*:*:*:*
mozillathunderbird0.7.1cpe:2.3:a:mozilla:thunderbird:0.7.1:*:*:*:*:*:*:*
mozillathunderbird0.7.2cpe:2.3:a:mozilla:thunderbird:0.7.2:*:*:*:*:*:*:*
mozillathunderbird0.7.3cpe:2.3:a:mozilla:thunderbird:0.7.3:*:*:*:*:*:*:*
conectivalinux9.0cpe:2.3:o:conectiva:linux:9.0:*:*:*:*:*:*:*
conectivalinux10.0cpe:2.3:o:conectiva:linux:10.0:*:*:*:*:*:*:*
redhatenterprise_linux2.1cpe:2.3:o:redhat:enterprise_linux:2.1:*:advanced_server:*:*:*:*:*
Rows per page:
1-10 of 341

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.116

Percentile

95.3%