← Back to CVE List
Vulnerability Intelligence Report

CVE-2004-0902

Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII hostname.

No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:10.14%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
mozilla mozilla 1.7, 1.7.1, 1.7.2
mozilla thunderbird 0.7, 0.7.1, 0.7.2, 0.7.3
conectiva linux 9.0, 10.0
redhat enterprise_linux 2.1, 3.0
redhat enterprise_linux_desktop 3.0
redhat fedora_core core_1.0
redhat linux 7.3, 9.0
redhat linux_advanced_workstation 2.1
suse suse_linux 1.0, 8, 8.1, 8.2, 9.0, 9.1

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
10.139%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2004-09-23T00:00:00
Published2004-09-24T04:00:00
Patch Date2004-09-16
Last Updated2024-08-08T00:31:48

LINK COPIED TO CLIPBOARD