7.5

CVE-2003-0346

Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftDirectx Version5.2
MicrosoftDirectx Version6.1
MicrosoftDirectx Version7.0
MicrosoftDirectx Version7.0a
MicrosoftDirectx Version8.1
MicrosoftDirectx Version9.0a
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 25.68% 0.957
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P