Vulnerability Description
Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 2000 | All versions |
| Microsoft | Windows 2000 Terminal Services | All versions |
| Microsoft | Windows 98 | All versions |
| Microsoft | Windows 98Se | All versions |
| Microsoft | Windows Me | All versions |
| Microsoft | Windows Nt | 4.0 |
| Microsoft | Windows Xp | All versions |
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0139.html
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=26
- http://marc.info/?l=bugtraq&m=104812108307645&w=2
- http://www.securityfocus.com/bid/7146PatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-00
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0139.html
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=26
- http://marc.info/?l=bugtraq&m=104812108307645&w=2
- http://www.securityfocus.com/bid/7146PatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-00
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
FAQ
What is CVE-2003-0010?
CVE-2003-0010 is a vulnerability with a CVSS score of 7.5 (HIGH). Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a...
How severe is CVE-2003-0010?
CVE-2003-0010 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-0010?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows 2000, Microsoft Windows 2000 Terminal Services, Microsoft Windows 98, Microsoft Windows 98Se, Microsoft Windows Me.