Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2024-08-07T21:44:06.238Z
Reserved: 2005-04-22T00:00:00
Link: CVE-2005-1208
No data.
Status : Deferred
Published: 2005-06-14T04:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2005-1208
No data.
OpenCVE Enrichment
No data.
Weaknesses