Vulnerabilities > CVE-2004-0978 - Out-of-bounds Write vulnerability in Microsoft Internet Explorer 5.01/5.5/6
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Heap-based buffer overflow in the Hrtbeat.ocx (Heartbeat) ActiveX control for Internet Explorer 5.01 through 6, when users who visit online gaming sites that are associated with MSN, allows remote attackers to execute arbitrary code via the SetupData parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 | |
OS | 12 |
Common Weakness Enumeration (CWE)
References
- http://marc.info/?l=bugtraq&m=110616221411579&w=2
- http://marc.info/?l=bugtraq&m=110616221411579&w=2
- http://www.kb.cert.org/vuls/id/673134
- http://www.kb.cert.org/vuls/id/673134
- http://www.ngssoftware.com/advisories/heartbeatfull.txt
- http://www.ngssoftware.com/advisories/heartbeatfull.txt
- http://www.securityfocus.com/bid/11367
- http://www.securityfocus.com/bid/11367
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17714
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17714