Vulnerability Description
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Avaya | Ip600 Media Servers | All versions |
| Avaya | Definity One Media Server | All versions |
| Avaya | S8100 | All versions |
| Avaya | Modular Messaging Message Storage Server | s3400 |
| Microsoft | Windows 2000 | All versions |
| Microsoft | Windows 2003 Server | enterprise |
| Microsoft | Windows 98 | All versions |
| Microsoft | Windows 98Se | All versions |
| Microsoft | Windows Me | All versions |
| Microsoft | Windows Nt | 4.0 |
| Microsoft | Windows Xp | All versions |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023919.html
- http://www.kb.cert.org/vuls/id/920060PatchThird Party AdvisoryUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-196A.htmlPatchThird Party AdvisoryUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-02
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16586
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023919.html
- http://www.kb.cert.org/vuls/id/920060PatchThird Party AdvisoryUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-196A.htmlPatchThird Party AdvisoryUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-02
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16586
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
FAQ
What is CVE-2004-0201?
CVE-2004-0201 is a vulnerability with a CVSS score of 10.0 (HIGH). Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CH...
How severe is CVE-2004-0201?
CVE-2004-0201 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0201?
Check the references section above for vendor advisories and patch information. Affected products include: Avaya Ip600 Media Servers, Avaya Definity One Media Server, Avaya S8100, Avaya Modular Messaging Message Storage Server, Microsoft Windows 2000.