Vulnerability Details CVE-2004-1305
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.774
EPSS Ranking 98.9%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2004-1305
-
cpe:2.3:a:nortel:ip_softphone_2050:-
-
cpe:2.3:a:nortel:media_communication_server_5100:3.0
-
cpe:2.3:a:nortel:media_communication_server_5200:3.0
-
cpe:2.3:a:nortel:media_processing_server:-
-
cpe:2.3:a:nortel:periphonics:-
-
cpe:2.3:a:nortel:symposium_agent:-
-
cpe:2.3:a:nortel:symposium_network_control_center:-
-
cpe:2.3:a:nortel:symposium_tapi_service_provider:-
-
cpe:2.3:a:nortel:symposium_web_centre_portal:-
-
cpe:2.3:a:nortel:symposium_web_client:-
-
cpe:2.3:h:nortel:symposium_call_center_server:-
-
cpe:2.3:h:nortel:symposium_express_call_center:-
-
cpe:2.3:o:microsoft:windows_2000:-
-
cpe:2.3:o:microsoft:windows_2000:beta3
-
cpe:2.3:o:microsoft:windows_2003_server:enterprise
-
cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit
-
cpe:2.3:o:microsoft:windows_2003_server:r2
-
cpe:2.3:o:microsoft:windows_2003_server:standard
-
cpe:2.3:o:microsoft:windows_2003_server:web
-
cpe:2.3:o:microsoft:windows_98:-
-
cpe:2.3:o:microsoft:windows_98se:-
-
cpe:2.3:o:microsoft:windows_me:-
-
cpe:2.3:o:microsoft:windows_nt:4.0
-
cpe:2.3:o:microsoft:windows_xp:*
-
cpe:2.3:o:microsoft:windows_xp:-