CVE-2004-0904
Mozilla Firefox - Remote Code Execution via BMP Decoder Integer Overflow
Title source: llmDescription
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
References (11)
Core 11
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17381
Vendor Advisory vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2004_36_mozilla.html
Mailing List vendor-advisory
x_refsource_fedora
http://marc.info/?l=bugtraq&m=109900315219363&w=2
Vendor Advisory x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=255067
Various Sources x_refsource_confirm
http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200409-26.xml
Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/11171
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA04-261A.html
Mailing List vendor-advisory
x_refsource_hp
http://marc.info/?l=bugtraq&m=109698896104418&w=2
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10952
Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/847200
Scores
EPSS
0.0801
EPSS Percentile
94.1%
Details
Status
published
Products (26)
conectiva/linux
9.0
conectiva/linux
10.0
mozilla/firefox
0.8
mozilla/firefox
0.9 (2 CPE variants)
mozilla/firefox
0.9.1
mozilla/firefox
0.9.2
mozilla/firefox
0.9.3
mozilla/mozilla
1.7 (2 CPE variants)
mozilla/mozilla
1.7.1
mozilla/mozilla
1.7.2
... and 16 more
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026