[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Windows Animated Cursor Remote Code Execution Vulnerability

ID: oval:org.mitre.oval:def:1854Date: (C)2007-04-09   (M)2021-06-02
Class: VULNERABILITYFamily: windows




Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.

Platform:
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Reference:
CVE-2007-0038
CVE    1
CVE-2007-0038
CPE    8
cpe:/o:microsoft:windows_server_2003::sp1:x86
cpe:/o:microsoft:windows_server_2003::gold:x86
cpe:/o:microsoft:windows_vista::gold
cpe:/o:microsoft:windows_2000::sp4
...

© SecPod Technologies