CVE Vulnerabilities

CVE-2005-1208

Published: Jun 14, 2005 | Modified: Oct 12, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a ms-its: URL in Internet Explorer.

Affected Software

Name Vendor Start Version End Version
Windows_2000 Microsoft * *
Windows_2003_server Microsoft 64-bit (including) 64-bit (including)
Windows_2003_server Microsoft datacenter_64-bit-sp1 (including) datacenter_64-bit-sp1 (including)
Windows_2003_server Microsoft datacenter_64-bit-sp1_beta_1 (including) datacenter_64-bit-sp1_beta_1 (including)
Windows_2003_server Microsoft enterprise (including) enterprise (including)
Windows_2003_server Microsoft enterprise-sp1 (including) enterprise-sp1 (including)
Windows_2003_server Microsoft enterprise-sp1_beta_1 (including) enterprise-sp1_beta_1 (including)
Windows_2003_server Microsoft enterprise_64-bit (including) enterprise_64-bit (including)
Windows_2003_server Microsoft enterprise_64-bit-sp1 (including) enterprise_64-bit-sp1 (including)
Windows_2003_server Microsoft enterprise_64-bit-sp1_beta_1 (including) enterprise_64-bit-sp1_beta_1 (including)
Windows_2003_server Microsoft r2 (including) r2 (including)
Windows_2003_server Microsoft r2-sp1 (including) r2-sp1 (including)
Windows_2003_server Microsoft r2-sp1_beta_1 (including) r2-sp1_beta_1 (including)
Windows_2003_server Microsoft standard (including) standard (including)
Windows_2003_server Microsoft standard-sp1 (including) standard-sp1 (including)
Windows_2003_server Microsoft standard-sp1_beta_1 (including) standard-sp1_beta_1 (including)
Windows_2003_server Microsoft standard_64-bit (including) standard_64-bit (including)
Windows_2003_server Microsoft web (including) web (including)
Windows_2003_server Microsoft web-sp1 (including) web-sp1 (including)
Windows_2003_server Microsoft web-sp1_beta_1 (including) web-sp1_beta_1 (including)
Windows_98 Microsoft * *
Windows_xp Microsoft * *

References