peter bassill · operator
$ cve CVE-2004-1050 JSON

CVE-2004-1050 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 67.1% (pctl 99)

Patch early

A public exploit exists.

Description

Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS67.06% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (7)

VendorProduct
avayadefinity one media server
avayaip600 media servers
avayamodular messaging message storage server
avayas3400
avayas8100
microsoftie
microsoftinternet explorer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD