AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2004-0904

HIGH · CVSS 10 EPSS 8.01%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2004-12-31 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 10.0. It affects Firefox. It may be remotely exploitable.

CVE
CVE-2004-0904
Severity
HIGH
CVSS
10
EPSS
8.01%
Firefox

Original NVD Description

Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.