CVE-2010-1098
Microsoft Windows XP and Vista - Denial of Service via ANI File BITMAPINFO Header
Title source: llmDescription
The ANI parser in Microsoft Windows before 7 on the x86 platform, as used in Internet Explorer and other applications, allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted biClrUsed value in the BITMAPINFO header of a .ANI file.
References (4)
Core 4
Core References
Issue Tracking x_refsource_misc
http://code.google.com/p/skylined/issues/detail?id=3
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/38579
URL Repurposed x_refsource_misc
http://skypher.com/index.php/2010/03/08/ani-file-bitmapinfoheader-biclrused-bounds-check-missing/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/56756
Scores
EPSS
0.1505
EPSS Percentile
96.4%
Details
CWE
CWE-399
Status
published
Products (2)
microsoft/windows_vista
microsoft/windows_xp
Published
Mar 24, 2010
Tracked Since
Feb 18, 2026