← back
CVE-2004-0200

CVE-2004-0200

35Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 49%
from disclosure to weapon5 days
Published on NVDSep 17
1st PoC+5d
exploitation probability
49%top 1% of all CVEs
observed exploitation
nono source reports it
6 public exploit(s)
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.