CVE-2004-0200

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/09/2004
Last modified:
03/04/2025

Description

Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:.net_framework:1.0:sp2:sdk:*:*:*:*:*
cpe:2.3:a:microsoft:digital_image_pro:7.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:digital_image_pro:9:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:digital_image_suite:9:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:frontpage:2002:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:frontpage:2003:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:greetings:2002:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:infopath:2003:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2003:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:onenote:2003:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:outlook:2002:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:outlook:2003:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools