CVE-2003-1048

HIGH

Internet Explorer 6.x - Denial of Service via Malformed GIF Image

Title source: llm
STIX 2.1

Description

Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.

References (16)

Core 16
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/685364
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16804
Broken Link, Third Party Advisory, VDB Entry, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/8530
Patch, Vendor Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-025
Broken Link, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA04-212A.html
Broken Link third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/o-191.shtml

Scores

CVSS v3 7.8
EPSS 0.2663
EPSS Percentile 97.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-415
Status published
Products (10)
microsoft/internet_explorer 5.01 sp2 (3 CPE variants)
microsoft/internet_explorer 5.5 sp2
microsoft/internet_explorer 6.0 (2 CPE variants)
microsoft/outlook 2000 sp2 (3 CPE variants)
microsoft/windows_98
microsoft/windows_98se
microsoft/windows_me
microsoft/windows_nt 4.0 sp6 (3 CPE variants)
microsoft/windows_server_2003
microsoft/windows_xp (2 CPE variants)
Published Jul 27, 2004
Tracked Since Feb 18, 2026