7.5
CVSSv2

CVE-2005-0416

Published: 27/04/2005 Updated: 30/04/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote malicious users to execute arbitrary code via the AnimationHeaderBlock length field, which leads to a stack-based buffer overflow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 2000

microsoft windows 2003 server enterprise_64-bit

microsoft windows 2003 server web

microsoft windows 98

microsoft windows 2003 server r2

microsoft windows 2003 server standard

microsoft windows nt 4.0

microsoft windows 2003 server enterprise

microsoft windows 98se

microsoft windows me

microsoft windows xp

Exploits

/* Modified by Vertygo aka Ivanm (ivanm@blicnet) all credits goes to houseofdabus Berend-Jan Wever and to milw0rm*/ /* Added stringh /str0ke */ /* HOD-ms05002-ani-explc: 2005-01-10: PUBLIC v02 * * Copyright (c) 2004-2005 houseofdabus * * (MS05-002) Microsoft Internet Explorer ANI Files Handling Exploit * (CAN-2004-1049) * * * * ...
/* Added stringh /str0ke */ /* HOD-ms05002-ani-explc: 2005-01-10: PUBLIC v02 * * Copyright (c) 2004-2005 houseofdabus * * (MS05-002) Microsoft Internet Explorer ANI Files Handling Exploit * (CAN-2004-1049) * * * * ::[ houseofdabus ]:: * * * * (universal -- for all affected systems) * --------------------------- ...