cbcvebase.
CVE-2004-0200
published 2004-09-28

CVE-2004-0200: Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to…

critical9.3CVSS 3.1
AVNACMAuNCCICAC
EXPLOIT
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftdigital_image_pro
microsoftdigital_image_pro
microsoftdigital_image_suite
microsoftexcel
microsoftexcel
microsoftfrontpage
microsoftfrontpage
microsoftgreetings
microsoftinfopath
microsoftnet_framework
microsoftoffice
microsoftoffice
microsoftonenote
microsoftoutlook
microsoftoutlook
microsoftpicture_it
microsoftpicture_it
microsoftpicture_it
microsoftpowerpoint
microsoftpowerpoint
microsoftproject
microsoftproject
microsoftpublisher
microsoftpublisher
microsoftvisio