CVE Vulnerabilities

CVE-2004-0901

Published: Jan 10, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka Font Conversion Vulnerability, a different vulnerability than CVE-2004-0571.

Affected Software

NameVendorStart VersionEnd Version
Windows_2000Microsoft**
Windows_2003_serverMicrosoftenterprise (including)enterprise (including)
Windows_2003_serverMicrosoftenterprise_64-bit (including)enterprise_64-bit (including)
Windows_2003_serverMicrosoftr2 (including)r2 (including)
Windows_2003_serverMicrosoftstandard (including)standard (including)
Windows_2003_serverMicrosoftweb (including)web (including)
Windows_98Microsoft**
Windows_98seMicrosoft**
Windows_meMicrosoft**
Windows_ntMicrosoft4.0 (including)4.0 (including)
Windows_ntMicrosoft4.0-sp1 (including)4.0-sp1 (including)
Windows_ntMicrosoft4.0-sp2 (including)4.0-sp2 (including)
Windows_ntMicrosoft4.0-sp3 (including)4.0-sp3 (including)
Windows_ntMicrosoft4.0-sp4 (including)4.0-sp4 (including)
Windows_ntMicrosoft4.0-sp5 (including)4.0-sp5 (including)
Windows_ntMicrosoft4.0-sp6 (including)4.0-sp6 (including)
Windows_ntMicrosoft4.0-sp6a (including)4.0-sp6a (including)
Windows_xpMicrosoft**

References