CVE-2004-1305

Nortel IP Softphone 2050 - Denial of Service

Title source: rule

Description

The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Flashsky · htmldoswindows
https://www.exploit-db.com/exploits/721

Scores

EPSS 0.7847
EPSS Percentile 99.0%

Details

Status published
Products (11)
microsoft/windows_2000 (5 CPE variants)
microsoft/windows_2003_server enterprise
microsoft/windows_2003_server enterprise_64-bit
microsoft/windows_2003_server r2 (2 CPE variants)
microsoft/windows_2003_server standard
microsoft/windows_2003_server web
microsoft/windows_98
microsoft/windows_98se
microsoft/windows_me
microsoft/windows_nt 4.0 (31 CPE variants)
... and 1 more
Published Dec 23, 2004
Tracked Since Feb 18, 2026