Vulnerability Details CVE-2004-0201
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.386
EPSS Ranking 97.0%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2004-0201
-
cpe:2.3:a:avaya:ip600_media_servers:-
-
cpe:2.3:a:avaya:ip600_media_servers:r10
-
cpe:2.3:h:avaya:definity_one_media_server:-
-
cpe:2.3:h:avaya:definity_one_media_server:r10
-
cpe:2.3:h:avaya:definity_one_media_server:r9
-
-
cpe:2.3:o:avaya:modular_messaging_message_storage_server:s3400
-
cpe:2.3:o:microsoft:windows_2000:-
-
cpe:2.3:o:microsoft:windows_2000:beta3
-
cpe:2.3:o:microsoft:windows_2003_server:enterprise
-
cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit
-
cpe:2.3:o:microsoft:windows_2003_server:r2
-
cpe:2.3:o:microsoft:windows_2003_server:standard
-
cpe:2.3:o:microsoft:windows_2003_server:web
-
cpe:2.3:o:microsoft:windows_98:-
-
cpe:2.3:o:microsoft:windows_98se:-
-
cpe:2.3:o:microsoft:windows_me:-
-
cpe:2.3:o:microsoft:windows_nt:4.0
-
cpe:2.3:o:microsoft:windows_xp:*
-
cpe:2.3:o:microsoft:windows_xp:-