Tracker / CVE-2004-0200
CVE-2004-0200
High 9.3
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
Affected products and versions
| microsoft | .net_framework |
|---|---|
| microsoft | digital_image_pro |
| microsoft | digital_image_suite |
| microsoft | excel |
| microsoft | frontpage |
| microsoft | greetings |
| microsoft | infopath |
| microsoft | office |
| microsoft | onenote |
| microsoft | outlook |
| microsoft | picture_it |
| microsoft | powerpoint |
| microsoft | producer |
| microsoft | project |
| microsoft | publisher |
| microsoft | visio |
| microsoft | visual_basic |
| microsoft | visual_c\# |
| microsoft | visual_c\+\+ |
| microsoft | visual_j\#_.net |
| microsoft | visual_studio_.net |
| microsoft | windows_2003_server |
| microsoft | windows_xp |
| microsoft | word |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.