← Back

CVE-2004-0901

nvd nist
Published: Jan 10, 2005Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.

Affected (51)

7 products
Windows 2000
Windows 2003 Server
Windows 98
Windows 98se
Windows Me
Windows Nt
Windows Xp
Configuration A
51 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
All versions
All versions
All versions
All versions
All versions
Microsoft
Version enterprise
Version enterprise_64-bit
Version r2
Version r2
Version standard
Version web
All versions
All versions
All versions
Microsoft
Version 4.0
Version 4.0
Version 4.0
Version 4.0
Version 4.0 sp1
Version 4.0 sp1
Version 4.0 sp1
Version 4.0 sp1
Version 4.0 sp2
Version 4.0 sp2
Version 4.0 sp2
Version 4.0 sp2
Version 4.0 sp3
Version 4.0 sp3
Version 4.0 sp3
Version 4.0 sp3
Version 4.0 sp4
Version 4.0 sp4
Version 4.0 sp4
Version 4.0 sp4
Version 4.0 sp5
Version 4.0 sp5
Version 4.0 sp5
Version 4.0 sp5
Version 4.0 sp6
Version 4.0 sp6
Version 4.0 sp6
Version 4.0 sp6
Version 4.0 sp6a
Version 4.0 sp6a
Version 4.0 sp6a
Microsoft
All versions
All versions
All versions
All versions
All versions
All versions

References (24)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.