← Back

CVE-2005-1208

nvd nist
Published: Jun 14, 2005Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.

Affected (37)

4 products
Windows 2000
Windows 2003 Server
Windows 98
Windows Xp
Configuration A
37 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Microsoft
Version 64-bit
Version datacenter_64-bit sp1
Version datacenter_64-bit sp1_beta_1
Version enterprise
Version enterprise sp1
Version enterprise sp1_beta_1
Version enterprise_64-bit
Version enterprise_64-bit sp1
Version enterprise_64-bit sp1_beta_1
Version r2
Version r2
Version r2
Version r2 sp1
Version r2 sp1_beta_1
Version standard
Version standard sp1
Version standard sp1_beta_1
Version standard_64-bit
Version web
Version web sp1
Version web sp1_beta_1
All versions
Microsoft
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions

References (18)

Source: secure@microsoft.com
PatchVendor Advisory
Source: secure@microsoft.com
PatchVendor Advisory
Source: secure@microsoft.com
PatchThird Party AdvisoryUS Government Resource
Source: secure@microsoft.com
Source: secure@microsoft.com
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource

Timeline

No history available yet.