[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-1208Date: (C)2005-06-14   (M)2023-12-22


Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
BID-13953
SECUNIA-15683
http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0062.html
MS05-026
TA05-165A
VU#851869
oval:org.mitre.oval:def:1057
oval:org.mitre.oval:def:381
oval:org.mitre.oval:def:463

CPE    10
cpe:/o:microsoft:windows_xp::sp1:tablet_pc
cpe:/o:microsoft:windows_xp::sp1:media_center
cpe:/o:microsoft:windows_xp::sp2:media_center
cpe:/o:microsoft:windows_98::gold
...
OVAL    3
oval:org.mitre.oval:def:1057
oval:org.mitre.oval:def:381
oval:org.mitre.oval:def:463

© SecPod Technologies