10
CVSSv2

CVE-2004-0575

Published: 03/11/2004 Updated: 12/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote malicious users to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows xp

microsoft windows 2003 server r2

microsoft windows 2003 server 64-bit

Exploits

GetRight Skin File (*grs) Buffer Overflow May Let Remote Users Run Arbitrary Code Application: GetRight Headlight Software wwwgetrightcom Author: ATmaCA <atmaca@prohacknet> a remote user can create a malicious skin file (*grs) that, when loaded by the target user, will trigger a buffer overflow in DUNZIP32D ...
/* Microsoft Windows Vulnerability in Compressed (zipped) Folders (MS04-034) * * Tested under Windows XP SP0 Spanish/English * * Original Advisory: wwweeyecom/html/research/advisories/AD20041012Ahtml * Exploit Date: 21/10/2004 * * Tarako - Haxorcitoscom 2004 * * THIS PROGRAM IS FOR EDUCATIONAL PURPOSES *ONLY* IT IS PROVIDED "AS IS" * AND ...