CVE-2004-0902 - CVE House
Back to Database
Status published Critical CVE-2004-0902

Multiple heap-based buffer overflows in Mozilla Firefox before the Preview...

Vulnerability Description

Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII hostname.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-0902

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

mozilla, thunderbird, linux, enterprise linux, enterprise linux desktop, fedora core, linux advanced workstation, suse linux
Vulnerable Versions:
1.7, 1.7.1, 1.7.2, 0.7, 0.7.1, 0.7.2, 0.7.3, 9.0, 10.0, 2.1, 3.0, core_1.0, 7.3, 1.0, 8, 8.1, 8.2, 9.1

Timeline

Official Publish: September 24th, 2004
Last Modified: August 8th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.