Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
History
                    20 Nov 2024, 23:49
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://bugzilla.mozilla.org/show_bug.cgi?id=255067 - Vendor Advisory | |
| References | () http://marc.info/?l=bugtraq&m=109698896104418&w=2 - | |
| References | () http://marc.info/?l=bugtraq&m=109900315219363&w=2 - | |
| References | () http://security.gentoo.org/glsa/glsa-200409-26.xml - | |
| References | () http://www.kb.cert.org/vuls/id/847200 - Third Party Advisory, US Government Resource | |
| References | () http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3 - | |
| References | () http://www.novell.com/linux/security/advisories/2004_36_mozilla.html - | |
| References | () http://www.securityfocus.com/bid/11171 - Vendor Advisory | |
| References | () http://www.us-cert.gov/cas/techalerts/TA04-261A.html - US Government Resource | |
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/17381 - | |
| References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10952 - | 
Information
                Published : 2004-12-31 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2004-0904
Mitre link : CVE-2004-0904
CVE.ORG link : CVE-2004-0904
JSON object : View
Products Affected
                conectiva
- linux
redhat
- enterprise_linux_desktop
- linux_advanced_workstation
- enterprise_linux
- fedora_core
- linux
netscape
- navigator
mozilla
- mozilla
- thunderbird
- firefox
CWE
                