Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-1050
CVE-2004-1050
Description
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."
Affected products
28cpe:2.3:a:avaya:ip600_media_servers:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:avaya:ip600_media_servers:*:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip600_media_servers:r10:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip600_media_servers:r11:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip600_media_servers:r12:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip600_media_servers:r6:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip600_media_servers:r7:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip600_media_servers:r8:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip600_media_servers:r9:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*
cpe:2.3:h:avaya:definity_one_media_server:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:h:avaya:definity_one_media_server:*:*:*:*:*:*:*:*
- cpe:2.3:h:avaya:definity_one_media_server:r10:*:*:*:*:*:*:*
- cpe:2.3:h:avaya:definity_one_media_server:r11:*:*:*:*:*:*:*
- cpe:2.3:h:avaya:definity_one_media_server:r12:*:*:*:*:*:*:*
- cpe:2.3:h:avaya:definity_one_media_server:r6:*:*:*:*:*:*:*
- cpe:2.3:h:avaya:definity_one_media_server:r7:*:*:*:*:*:*:*
- cpe:2.3:h:avaya:definity_one_media_server:r8:*:*:*:*:*:*:*
- cpe:2.3:h:avaya:definity_one_media_server:r9:*:*:*:*:*:*:*
cpe:2.3:h:avaya:s8100:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:h:avaya:s8100:*:*:*:*:*:*:*:*
- cpe:2.3:h:avaya:s8100:r10:*:*:*:*:*:*:*
- cpe:2.3:h:avaya:s8100:r11:*:*:*:*:*:*:*
- cpe:2.3:h:avaya:s8100:r12:*:*:*:*:*:*:*
- cpe:2.3:h:avaya:s8100:r6:*:*:*:*:*:*:*
- cpe:2.3:h:avaya:s8100:r7:*:*:*:*:*:*:*
- cpe:2.3:h:avaya:s8100:r8:*:*:*:*:*:*:*
- cpe:2.3:h:avaya:s8100:r9:*:*:*:*:*:*:*
- cpe:2.3:o:avaya:modular_messaging_message_storage_server:s3400:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- www.kb.cert.org/vuls/id/842160nvdThird Party AdvisoryUS Government Resource
- www.us-cert.gov/cas/techalerts/TA04-315A.htmlnvdUS Government Resource
- www.us-cert.gov/cas/techalerts/TA04-336A.htmlnvdUS Government Resource
- lists.grok.org.uk/pipermail/full-disclosure/2004-October/028009.htmlnvd
- lists.grok.org.uk/pipermail/full-disclosure/2004-October/028035.htmlnvd
- marc.infonvd
- secunia.com/advisories/12959/nvd
- www.securityfocus.com/archive/1/379261nvd
- www.securityfocus.com/bid/11515nvd
- docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-040nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/17889nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1294nvd
News mentions
0No linked articles in our index yet.