CVE-2004-1050
Summary
| CVE | CVE-2004-1050 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability." |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Avaya | Definity One Media Server | All | All | All | All |
| Hardware | Avaya | Definity One Media Server | r10 | All | All | All |
| Hardware | Avaya | Definity One Media Server | r11 | All | All | All |
| Hardware | Avaya | Definity One Media Server | r12 | All | All | All |
| Hardware | Avaya | Definity One Media Server | r6 | All | All | All |
| Hardware | Avaya | Definity One Media Server | r7 | All | All | All |
| Hardware | Avaya | Definity One Media Server | r8 | All | All | All |
| Hardware | Avaya | Definity One Media Server | r9 | All | All | All |
| Application | Avaya | Ip600 Media Servers | All | All | All | All |
| Application | Avaya | Ip600 Media Servers | r10 | All | All | All |
| Application | Avaya | Ip600 Media Servers | r11 | All | All | All |
| Application | Avaya | Ip600 Media Servers | r12 | All | All | All |
| Application | Avaya | Ip600 Media Servers | r6 | All | All | All |
| Application | Avaya | Ip600 Media Servers | r7 | All | All | All |
| Application | Avaya | Ip600 Media Servers | r8 | All | All | All |
| Application | Avaya | Ip600 Media Servers | r9 | All | All | All |
| Operating System | Avaya | Modular Messaging Message Storage Server | s3400 | All | All | All |
| Hardware | Avaya | S3400 | All | All | All | All |
| Hardware | Avaya | S8100 | All | All | All | All |
| Hardware | Avaya | S8100 | r10 | All | All | All |
| Hardware | Avaya | S8100 | r11 | All | All | All |
| Hardware | Avaya | S8100 | r12 | All | All | All |
| Hardware | Avaya | S8100 | r6 | All | All | All |
| Hardware | Avaya | S8100 | r7 | All | All | All |
| Hardware | Avaya | S8100 | r8 | All | All | All |
| Hardware | Avaya | S8100 | r9 | All | All | All |
| Application | Microsoft | Ie | 6.0 | sp1 | All | All |
| Application | Microsoft | Internet Explorer | 6.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Security Bulletin MS04-040 - Critical | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| US-CERT Vulnerability Note VU#842160 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| US-CERT Technical Cyber Security Alert TA04-315A -- Buffer Overflow in Microsoft Internet Explorer | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| US-CERT Technical Cyber Security Alert TA04-336A -- Update for Microsoft Internet Explorer HTML Elements Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| [Full-Disclosure] python does mangleme (with IE bugs!) | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | |
| 'MSIE <IFRAME> and <FRAME> tag NAME property bufferoverflow PoC' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Secunia - Advisories - Internet Explorer HTML Elements Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Microsoft Internet Explorer Malformed IFRAME Remote Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [Full-Disclosure] python does mangleme (with IE bugs!) | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.