10
CVE-2004-0978
- EPSS 38.31%
- Veröffentlicht 09.02.2005 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:06:46
- Erkennungen
Heap-based buffer overflow in the Hrtbeat.ocx (Heartbeat) ActiveX control for Internet Explorer 5.01 through 6, when users who visit online gaming sites that are associated with MSN, allows remote attackers to execute arbitrary code via the SetupData parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 5.01 Update sp3
Microsoft ≫ Internet Explorer Version 5.01 Update sp4
Microsoft ≫ Internet Explorer Version 5.5 Update sp2
Microsoft ≫ Internet Explorer Version 6 Update -
Microsoft ≫ Windows Server 2003 Version -
Microsoft ≫ Windows Server 2003 Version - HwPlatform x64
Microsoft ≫ Windows Xp Version -
Microsoft ≫ Windows Xp Version - Update - HwPlatform x64
Microsoft ≫ Windows Xp Version - Update sp1
Microsoft ≫ Windows Xp Version - Update sp2
Microsoft ≫ Windows Server 2003 Version - HwPlatform x64
Microsoft ≫ Windows Xp Version -
Microsoft ≫ Windows Xp Version - Update - HwPlatform x64
Microsoft ≫ Windows Xp Version - Update sp1
Microsoft ≫ Windows Xp Version - Update sp2
Microsoft ≫ Internet Explorer Version 6 Update sp1
Microsoft ≫ Windows 2000 Version - Update sp3
Microsoft ≫ Windows 2000 Version - Update sp4
Microsoft ≫ Windows 98se Version -
Microsoft ≫ Windows Me Version -
Microsoft ≫ Windows Nt Version 4.0 Update sp6 SwEdition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp6a
Microsoft ≫ Windows Xp Version -
Microsoft ≫ Windows Xp Version - Update sp1
Microsoft ≫ Windows 2000 Version - Update sp4
Microsoft ≫ Windows 98se Version -
Microsoft ≫ Windows Me Version -
Microsoft ≫ Windows Nt Version 4.0 Update sp6 SwEdition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp6a
Microsoft ≫ Windows Xp Version -
Microsoft ≫ Windows Xp Version - Update sp1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 38.31% | 0.984 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038
http://marc.info/?l=bugtraq&m=110616221411579&w=2
http://www.kb.cert.org/vuls/id/673134
http://www.ngssoftware.com/advisories/heartbeatfull.txt
http://www.securityfocus.com/bid/11367
https://exchange.xforce.ibmcloud.com/vulnerabilities/17714