Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10873
https://exchange.xforce.ibmcloud.com/vulnerabilities/17380
http://www.us-cert.gov/cas/techalerts/TA04-261A.html
http://www.securityfocus.com/bid/11174
http://www.novell.com/linux/security/advisories/2004_36_mozilla.html
http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3
http://www.kb.cert.org/vuls/id/414240
http://security.gentoo.org/glsa/glsa-200409-26.xml
http://marc.info/?l=bugtraq&m=109900315219363&w=2