10

CVE-2003-1048

Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 5.01 Update sp2
Microsoft ≫ Internet Explorer Version 5.01 Update sp3
Microsoft ≫ Internet Explorer Version 5.01 Update sp4
Microsoft ≫ Internet Explorer Version 5.5 Update sp2
Microsoft ≫ Internet Explorer Version 6.0 Update -
Microsoft ≫ Internet Explorer Version 6.0 Update sp1
Microsoft ≫ Outlook Version 2000 Update sp2
Microsoft ≫ Outlook Version 2000 Update sp3
Microsoft ≫ Outlook Version 2000 Update sp4
Microsoft ≫ Windows 98 Version -
Microsoft ≫ Windows 98se Version -
Microsoft ≫ Windows Me Version -
Microsoft ≫ Windows Nt Version 4.0 Update sp6 SwEdition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp6a SwEdition server
Microsoft ≫ Windows Nt Version 4.0 Update sp6a SwEdition workstation
Microsoft ≫ Windows Xp Version -
Microsoft ≫ Windows Xp Version - Update sp1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 26.63% 0.978
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-415 Double Free

The product calls free() twice on the same memory address.

http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009445.html
Broken Link
http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009473.html
Broken Link
http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009506.html
Broken Link
http://www.ciac.org/ciac/bulletins/o-191.shtml
Broken Link
http://www.kb.cert.org/vuls/id/685364
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/8530
Third Party Advisory
Vendor Advisory
Broken Link
VDB Entry
http://www.us-cert.gov/cas/techalerts/TA04-212A.html
Third Party Advisory
US Government Resource
Broken Link
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-025
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/16804
Third Party Advisory
VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1793
Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A206
Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2100
Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A212
Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A236
Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A509
Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A517
Broken Link