[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-0200Date: (C)2004-09-28   (M)2024-03-01


Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
http://marc.info/?l=bugtraq&m=109524346729948&w=2
MS04-028
TA04-260A
VU#297462
oval:org.mitre.oval:def:1105
oval:org.mitre.oval:def:1721
oval:org.mitre.oval:def:2706
oval:org.mitre.oval:def:3038
oval:org.mitre.oval:def:3082
oval:org.mitre.oval:def:3320
oval:org.mitre.oval:def:3810
oval:org.mitre.oval:def:3881
oval:org.mitre.oval:def:4003
oval:org.mitre.oval:def:4216
oval:org.mitre.oval:def:4307
win-jpeg-bo(16304)

CPE    31
cpe:/a:microsoft:picture_it:2002
cpe:/a:microsoft:powerpoint:2002
cpe:/a:microsoft:digital_image_pro:9
cpe:/a:microsoft:powerpoint:2003
...
OVAL    11
oval:org.mitre.oval:def:3810
oval:org.mitre.oval:def:4307
oval:org.mitre.oval:def:3881
oval:org.mitre.oval:def:3320
...

© SecPod Technologies