2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2004-0200" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2004-09-28T04:00:00.000" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-20T23:47:59.090" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation."
} ,
{
"lang" : "es" ,
"value" : "Desbordamiento de b\u00fafer en el motor de proceso de JPEG (JPG) en GDIPlus.dll, usado en varios productos de Microsoft, permite a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n mediante un campo de longitud JPEG COM peque\u00f1o que es normalizado a una longitud de entero grande antes de una operaci\u00f3n de copia de memoria."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 9.3 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "COMPLETE" ,
"integrityImpact" : "COMPLETE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "COMPLETE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 8.6 ,
"impactScore" : 10.0 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : true ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : true
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-Other"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:.net_framework:1.0:sp2:sdk:*:*:*:*:*" ,
"matchCriteriaId" : "644D1C0E-482D-4C6D-AE9D-6B1F99306BC8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:digital_image_pro:7.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DED35E4C-1108-44AE-BA55-A008EB9864ED"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:digital_image_pro:9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BCC28680-6FA1-424A-BB8D-5E37E04D4089"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:digital_image_suite:9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "370835D5-D28A-4961-B1B4-72E889596D07"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "082D3262-87E3-4245-AD9C-02BE0871FA3B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5F79E0AB-7081-4F97-BFE4-9AF84F643B9A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:frontpage:2002:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6548F837-A687-4EEF-B754-DAA834B34FA3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:frontpage:2003:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3C79FEE1-70A3-4A48-BE7B-0D18F0A5FA7F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:greetings:2002:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "69AFBA4D-6F42-4ED9-9DF4-4A9C29B3ED8F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:infopath:2003:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "345BC07E-1558-4C27-BF1A-C13547D175FC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:office:2003:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DB7EA4CC-E705-42DB-86B6-E229DA36B66D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*" ,
"matchCriteriaId" : "79BA1175-7F02-4435-AEA6-1BA8AADEB7EF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:onenote:2003:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "36BA88A3-A31F-4F90-8913-67D5BC00E72D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:outlook:2002:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3FE6EAE0-5A8F-4A97-950B-879379A3C0F8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:outlook:2003:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C3189982-F780-4AC2-9663-E6D4DF9DD319"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:picture_it:7.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5D85EB5B-A9FE-497E-9922-6D6BDD0C6975"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:picture_it:9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A27F0EA6-C023-47C5-8F26-7E8A665533F5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:picture_it:2002:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "337555B3-6318-41FE-9AD7-6CEAA46F0DF7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:powerpoint:2002:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "711D9CC0-31B8-4511-A9F3-CA328A02ED84"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:powerpoint:2003:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F5611EFD-2C7C-47BA-83E5-947EA00D8E6C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:producer:*:gold:office_powerpoints:*:*:*:*:*" ,
"matchCriteriaId" : "999276CD-D074-4AB1-A53E-5133A3B7BFF6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:project:2002:sp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "9B14AE8E-1BFF-4458-87CC-357957F18F8A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:project:2003:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "34EFAEFE-2BDE-4111-91F5-E9F75ADFA920"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:publisher:2002:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "99ED878A-CFC5-4FD5-A403-EB16CC4F8BC0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:publisher:2003:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "617E8BE3-8AD0-42FC-BDEE-6B1F120AE512"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:visio:2002:sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "D0D2C5C3-225C-49DC-B9C7-C5BC05900F2E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:visio:2003:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "511E22C6-DB04-44A0-906D-F432DD42CA5C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:visual_basic:2002:*:.net_standard:*:*:*:*:*" ,
"matchCriteriaId" : "B3B633A9-519A-4179-9F10-3C2C5C9BA6B7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:visual_basic:2003:*:.net_standard:*:*:*:*:*" ,
"matchCriteriaId" : "D6D51C0E-BFF4-46A0-A8FD-45BE591DA347"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:visual_c\\#:2002:*:.net_standard:*:*:*:*:*" ,
"matchCriteriaId" : "1A1D8127-80AC-4D5B-9D1C-DA2406EF6666"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:visual_c\\#:2003:*:.net_standard:*:*:*:*:*" ,
"matchCriteriaId" : "8916C0DE-2759-4F97-B7D7-0BCFDC41AB4D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:visual_c\\+\\+:2002:*:.net_standard:*:*:*:*:*" ,
"matchCriteriaId" : "F1090984-34A7-4A21-B903-3FF5E5AB7D5D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:visual_c\\+\\+:2003:*:.net_standard:*:*:*:*:*" ,
"matchCriteriaId" : "A0BED5B2-5F57-4FC8-8B51-908A311B480B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:visual_j\\#_.net:2003:*:.net_standard:*:*:*:*:*" ,
"matchCriteriaId" : "CC13A32B-5F2A-42A4-95B5-D13EE78F013B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:visual_studio_.net:2002:gold:*:*:*:*:*:*" ,
"matchCriteriaId" : "E17BD019-DD35-413E-ACBA-2E77C8A1247D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:visual_studio_.net:2003:gold:*:*:*:*:*:*" ,
"matchCriteriaId" : "B9E6C132-4F4B-4FB0-9DDC-DD9750D8552D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:word:2002:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2D90B1E1-23CD-4595-AD78-DA1758E9896D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microsoft:word:2003:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "379C2A4A-78EF-473D-954B-F5DD76C3D6CF"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4E7FD818-322D-4089-A644-360C33943D29"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*" ,
"matchCriteriaId" : "91D6D065-A28D-49DA-B7F4-38421FF86498"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:microsoft:windows_xp:*:gold:*:*:*:*:*:*" ,
"matchCriteriaId" : "580B0C9B-DD85-40FA-9D37-BAC0C96D57FC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:64-bit:*:*:*:*:*" ,
"matchCriteriaId" : "B3BBBB2E-1699-4E1E-81BB-7A394DD6B31D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:microsoft:windows_xp:*:sp1:tablet_pc:*:*:*:*:*" ,
"matchCriteriaId" : "B9687E6C-EDE9-42E4-93D0-C4144FEC917A"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://marc.info/?l=bugtraq&m=109524346729948&w=2" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.kb.cert.org/vuls/id/297462" ,
"source" : "cve@mitre.org" ,
"tags" : [
"US Government Resource"
]
} ,
{
"url" : "http://www.us-cert.gov/cas/techalerts/TA04-260A.html" ,
"source" : "cve@mitre.org" ,
"tags" : [
"US Government Resource"
]
} ,
{
"url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-028" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/16304" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1105" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1721" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2706" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3038" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3082" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3320" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3810" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3881" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4003" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4216" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4307" ,
"source" : "cve@mitre.org"
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "http://marc.info/?l=bugtraq&m=109524346729948&w=2" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.kb.cert.org/vuls/id/297462" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"US Government Resource"
]
} ,
{
"url" : "http://www.us-cert.gov/cas/techalerts/TA04-260A.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"US Government Resource"
]
} ,
{
"url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-028" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/16304" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1105" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1721" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2706" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3038" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3082" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3320" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3810" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3881" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4003" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4216" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4307" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2023-04-24 12:24:31 +02:00
}
]
}