CVE-2010-1098
high · 7.1The ANI parser in Microsoft Windows before 7 on the x86 platform, as used in Internet Explorer and other applications, allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted biClrUsed value in the BITMAPINFO header of a .ANI file.
7.1
CVSS
15.0%
EPSS (exploit prob.)
97th
EPSS percentile
2010-03-24
Published
AV:N/AC:M/Au:N/C:N/I:N/A:C
Weaknesses
CWE-399
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | windows_vista | all versions |
| microsoft | windows_xp | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://code.google.com/p/skylined/issues/detail?id=3
- http://skypher.com/index.php/2010/03/08/ani-file-bitmapinfoheader-biclrused-bounds-check-missing/
- http://www.securityfocus.com/bid/38579
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56756
- http://code.google.com/p/skylined/issues/detail?id=3
- http://skypher.com/index.php/2010/03/08/ani-file-bitmapinfoheader-biclrused-bounds-check-missing/
- http://www.securityfocus.com/bid/38579
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56756
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2010-1098