9.3

CVE-2004-0200

Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft.Net Framework Version1.0 Updatesp2 Editionsdk
MicrosoftDigital Image Pro Version7.0
MicrosoftExcel Version2002
MicrosoftExcel Version2003
MicrosoftFrontpage Version2002
MicrosoftFrontpage Version2003
MicrosoftGreetings Version2002
MicrosoftInfopath Version2003
MicrosoftOffice Version2003
MicrosoftOffice Versionxp Updatesp3
MicrosoftOnenote Version2003
MicrosoftOutlook Version2002
MicrosoftOutlook Version2003
MicrosoftPicture It Version7.0
MicrosoftPicture It Version9
MicrosoftPicture It Version2002
MicrosoftPowerpoint Version2002
MicrosoftPowerpoint Version2003
MicrosoftProducer Updategold Editionoffice_powerpoints
MicrosoftProject Version2002 Updatesp1
MicrosoftProject Version2003
MicrosoftPublisher Version2002
MicrosoftPublisher Version2003
MicrosoftVisio Version2002 Updatesp2
MicrosoftVisio Version2003
MicrosoftVisual Basic Version2002 Edition.net_standard
MicrosoftVisual Basic Version2003 Edition.net_standard
MicrosoftVisual Studio .Net Version2002 Updategold
MicrosoftVisual Studio .Net Version2003 Updategold
MicrosoftWord Version2002
MicrosoftWord Version2003
MicrosoftWindows Xp Edition64-bit
MicrosoftWindows Xp Updategold
MicrosoftWindows Xp Updatesp1 Edition64-bit
MicrosoftWindows Xp Updatesp1 Editiontablet_pc
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 76.69% 0.989
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C