CVE-2004-1361

3 documents3 sources
Severity
5.0MEDIUM
EPSS
29.1%
top 3.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 23
Latest updateApr 29

Description

Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a malformed .hlp file, which leads to a heap-based buffer overflow.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-5pqc-wjgq-r2x7: Integer underflow in winhlp322022-04-29
CVEList
CVE-2004-1361: Integer underflow in winhlp322005-01-19
CVE-2004-1361 (MEDIUM CVSS 5) | Integer underflow in winhlp32.exe i | cvebase.io