CVE-2004-1050

Exp

Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."

Published: 2004-12-31 Last update: 2026-04-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2004-1050 is rated High Exploit Risk (84.7/100): CVSS Critical severity, with high exploitation likelihood (EPSS 67.06%, 99th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2004-1050

EDB-ID Source Kind Published Link
612 exploit_db edb 2004-11-02 Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2004-1050

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 81.51% 67.06% -14.44%
2 2026-01-11 79.09% 81.51% +2.42%
3 2025-10-13 79.09%

Full EPSS history (13 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2004-1050

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
10.0 2.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 10.0 [email protected]

Weakness enumeration for CVE-2004-1050

Affected software / configurations for CVE-2004-1050

Vendor Product Version Raw CPE
avaya ip600_media_servers cpe:2.3:a:avaya:ip600_media_servers:*:*:*:*:*:*:*:*
avaya ip600_media_servers r6 cpe:2.3:a:avaya:ip600_media_servers:r6:*:*:*:*:*:*:*
avaya ip600_media_servers r7 cpe:2.3:a:avaya:ip600_media_servers:r7:*:*:*:*:*:*:*
avaya ip600_media_servers r8 cpe:2.3:a:avaya:ip600_media_servers:r8:*:*:*:*:*:*:*
avaya ip600_media_servers r9 cpe:2.3:a:avaya:ip600_media_servers:r9:*:*:*:*:*:*:*
avaya ip600_media_servers r10 cpe:2.3:a:avaya:ip600_media_servers:r10:*:*:*:*:*:*:*
avaya ip600_media_servers r11 cpe:2.3:a:avaya:ip600_media_servers:r11:*:*:*:*:*:*:*
avaya ip600_media_servers r12 cpe:2.3:a:avaya:ip600_media_servers:r12:*:*:*:*:*:*:*
microsoft ie 6.0 cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
microsoft internet_explorer 6.0 cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*
avaya definity_one_media_server cpe:2.3:h:avaya:definity_one_media_server:*:*:*:*:*:*:*:*
avaya definity_one_media_server r6 cpe:2.3:h:avaya:definity_one_media_server:r6:*:*:*:*:*:*:*
avaya definity_one_media_server r7 cpe:2.3:h:avaya:definity_one_media_server:r7:*:*:*:*:*:*:*
avaya definity_one_media_server r8 cpe:2.3:h:avaya:definity_one_media_server:r8:*:*:*:*:*:*:*
avaya definity_one_media_server r9 cpe:2.3:h:avaya:definity_one_media_server:r9:*:*:*:*:*:*:*
avaya definity_one_media_server r10 cpe:2.3:h:avaya:definity_one_media_server:r10:*:*:*:*:*:*:*
avaya definity_one_media_server r11 cpe:2.3:h:avaya:definity_one_media_server:r11:*:*:*:*:*:*:*
avaya definity_one_media_server r12 cpe:2.3:h:avaya:definity_one_media_server:r12:*:*:*:*:*:*:*
avaya s3400 cpe:2.3:h:avaya:s3400:*:*:*:*:*:*:*:*
avaya s8100 cpe:2.3:h:avaya:s8100:*:*:*:*:*:*:*:*
avaya s8100 r6 cpe:2.3:h:avaya:s8100:r6:*:*:*:*:*:*:*
avaya s8100 r7 cpe:2.3:h:avaya:s8100:r7:*:*:*:*:*:*:*
avaya s8100 r8 cpe:2.3:h:avaya:s8100:r8:*:*:*:*:*:*:*
avaya s8100 r9 cpe:2.3:h:avaya:s8100:r9:*:*:*:*:*:*:*
avaya s8100 r10 cpe:2.3:h:avaya:s8100:r10:*:*:*:*:*:*:*
avaya s8100 r11 cpe:2.3:h:avaya:s8100:r11:*:*:*:*:*:*:*
avaya s8100 r12 cpe:2.3:h:avaya:s8100:r12:*:*:*:*:*:*:*
avaya modular_messaging_message_storage_server s3400 cpe:2.3:o:avaya:modular_messaging_message_storage_server:s3400:*:*:*:*:*:*:*

References for CVE-2004-1050

URL Tags
http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028009.html
http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028035.html
http://marc.info/?l=bugtraq&m=109942758911846&w=2
http://secunia.com/advisories/12959/
http://www.kb.cert.org/vuls/id/842160 Third Party Advisory US Government Resource
http://www.securityfocus.com/archive/1/379261
http://www.securityfocus.com/bid/11515
http://www.us-cert.gov/cas/techalerts/TA04-315A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA04-336A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-040
https://exchange.xforce.ibmcloud.com/vulnerabilities/17889
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1294
cvelogic Threat Intelligence