10

CVE-2003-1048

Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftInternet Explorer Version5.01 Updatesp2
MicrosoftInternet Explorer Version5.01 Updatesp3
MicrosoftInternet Explorer Version5.01 Updatesp4
MicrosoftInternet Explorer Version5.5 Updatesp2
MicrosoftInternet Explorer Version6.0 Update-
MicrosoftInternet Explorer Version6.0 Updatesp1
MicrosoftOutlook Version2000 Updatesp2
MicrosoftOutlook Version2000 Updatesp3
MicrosoftOutlook Version2000 Updatesp4
MicrosoftWindows 98 Version-
MicrosoftWindows 98se Version-
MicrosoftWindows Me Version-
MicrosoftWindows Nt Version4.0 Updatesp6 SwEditionterminal_server
MicrosoftWindows Nt Version4.0 Updatesp6a SwEditionserver
MicrosoftWindows Nt Version4.0 Updatesp6a SwEditionworkstation
MicrosoftWindows Xp Version-
MicrosoftWindows Xp Version- Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 47.17% 0.976
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-415 Double Free

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

http://www.kb.cert.org/vuls/id/685364
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/8530
Third Party Advisory
Vendor Advisory
Broken Link
VDB Entry
http://www.us-cert.gov/cas/techalerts/TA04-212A.html
Third Party Advisory
US Government Resource
Broken Link