CVE-2004-1639: Medium severity Mozilla Firefox vulnerability
Published Oct 26, 2004
·Updated
Mozilla Firefox before 0.10, Mozilla 5.0, and Gecko 20040913 allows remote attackers to cause a denial of service (application crash or memory consumption) via a large binary file with a .html extension.
Affected Software
6 affected components
Mozilla Firefox<=0.10
Mozilla Gecko=2004-09-13
Mozilla Mozilla=5.0
Mozilla Firefox<=0.10
Mozilla Mozilla=5.0
Mozilla Gecko=2004-09-13
Event History
Oct 26, 2004
CVE Published
04:00 AM
Feb 20, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1639?
CVE-2004-1639 is classified as a denial of service vulnerability.
2
Which software is affected by CVE-2004-1639?
CVE-2004-1639 affects Mozilla Firefox versions before 0.10, Mozilla 5.0, and Gecko version 2004-09-13.
3
How can I mitigate the risk of CVE-2004-1639?
To mitigate the risk of CVE-2004-1639, users should upgrade to a version of Mozilla Firefox later than 0.10 or a later version of Mozilla or Gecko.
4
What type of attack does CVE-2004-1639 involve?
CVE-2004-1639 involves a denial of service attack that can cause application crashes or excessive memory consumption.
5
Is there a workaround for CVE-2004-1639?
There are no specific workarounds for CVE-2004-1639; the recommended solution is to update the affected software.