← All CVEs

CVE-2007-0038

high · 9.3

Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.

9.3
CVSS
72.9%
EPSS (exploit prob.)
99th
EPSS percentile
2007-03-30
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
microsoftwindows_2000all versions
microsoftwindows_2003_servergold
microsoftwindows_2003_servergold
microsoftwindows_2003_servergold
microsoftwindows_2003_serversp1
microsoftwindows_2003_serversp1
microsoftwindows_2003_serversp2
microsoftwindows_2003_serversp2
microsoftwindows_2003_serversp2
microsoftwindows_vistaall versions
microsoftwindows_vistaall versions
microsoftwindows_xpall versions
microsoftwindows_xpall versions
microsoftwindows_xpall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-0038