[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-1050Date: (C)2004-12-31   (M)2023-12-22


Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
BID-11515
SECUNIA-12959
http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028009.html
http://www.securityfocus.com/archive/1/379261
http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028035.html
http://marc.info/?l=bugtraq&m=109942758911846&w=2
MS04-040
TA04-315A
TA04-336A
VU#842160
ie-iframe-src-name-bo(17889)
oval:org.mitre.oval:def:1294

CPE    7
cpe:/h:avaya:definity_one_media_server:r10
cpe:/a:avaya:ip600_media_servers:r10
cpe:/h:avaya:s3400
cpe:/a:avaya:ip600_media_servers
...
OVAL    1
oval:org.mitre.oval:def:1294

© SecPod Technologies