CVE-2004-0200
HIGH 9.3EPSS 49.0%
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
- CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 49.02% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2004-09-17
- Updated
- 2024-08-08
ExploitDB entries (6)
- https://www.exploit-db.com/exploits/556
- https://www.exploit-db.com/exploits/480
- https://www.exploit-db.com/exploits/478
- https://www.exploit-db.com/exploits/475
- https://www.exploit-db.com/exploits/474
- https://www.exploit-db.com/exploits/472