7.5
CVE-2003-0818
- EPSS 90.19%
- Published 03.03.2004 05:00:00
- Last modified 03.04.2025 01:03:51
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.
Data is provided by the National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Updatesp1
Microsoft ≫ Windows 2000 Updatesp2
Microsoft ≫ Windows 2000 Updatesp3
Microsoft ≫ Windows 2003 Server Versionenterprise Edition64-bit
Microsoft ≫ Windows 2003 Server Versionenterprise_64-bit
Microsoft ≫ Windows 2003 Server Versionr2 Edition64-bit
Microsoft ≫ Windows 2003 Server Versionr2 Editiondatacenter_64-bit
Microsoft ≫ Windows 2003 Server Versionstandard Edition64-bit
Microsoft ≫ Windows 2003 Server Versionweb
Microsoft ≫ Windows Nt Version4.0 Editionserver
Microsoft ≫ Windows Nt Version4.0 Editionterminal_server
Microsoft ≫ Windows Nt Version4.0 Editionworkstation
Microsoft ≫ Windows Nt Version4.0 Updatesp1 Editionserver
Microsoft ≫ Windows Nt Version4.0 Updatesp1 Editionterminal_server
Microsoft ≫ Windows Nt Version4.0 Updatesp1 Editionworkstation
Microsoft ≫ Windows Nt Version4.0 Updatesp2 Editionserver
Microsoft ≫ Windows Nt Version4.0 Updatesp2 Editionterminal_server
Microsoft ≫ Windows Nt Version4.0 Updatesp2 Editionworkstation
Microsoft ≫ Windows Nt Version4.0 Updatesp3 Editionserver
Microsoft ≫ Windows Nt Version4.0 Updatesp3 Editionterminal_server
Microsoft ≫ Windows Nt Version4.0 Updatesp3 Editionworkstation
Microsoft ≫ Windows Nt Version4.0 Updatesp4 Editionserver
Microsoft ≫ Windows Nt Version4.0 Updatesp4 Editionterminal_server
Microsoft ≫ Windows Nt Version4.0 Updatesp4 Editionworkstation
Microsoft ≫ Windows Nt Version4.0 Updatesp5 Editionserver
Microsoft ≫ Windows Nt Version4.0 Updatesp5 Editionterminal_server
Microsoft ≫ Windows Nt Version4.0 Updatesp5 Editionworkstation
Microsoft ≫ Windows Nt Version4.0 Updatesp6 Editionserver
Microsoft ≫ Windows Nt Version4.0 Updatesp6 Editionterminal_server
Microsoft ≫ Windows Nt Version4.0 Updatesp6 Editionworkstation
Microsoft ≫ Windows Nt Version4.0 Updatesp6a Editionserver
Microsoft ≫ Windows Nt Version4.0 Updatesp6a Editionworkstation
Microsoft ≫ Windows Xp Edition64-bit
Microsoft ≫ Windows Xp Editionhome
Microsoft ≫ Windows Xp Updategold Editionprofessional
Microsoft ≫ Windows Xp Updatesp1 Edition64-bit
Microsoft ≫ Windows Xp Updatesp1 Editionhome
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 90.19% | 0.996 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|