Vulnerabilities > CVE-2002-1185 - Unspecified vulnerability in Microsoft IE and Internet Explorer

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
microsoft

Summary

Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."

Oval

  • accepted2014-02-24T04:03:17.576-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameChristine Walzer
      organizationThe MITRE Corporation
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."
    familywindows
    idoval:org.mitre.oval:def:393
    statusaccepted
    submitted2004-01-27T05:00:00.000-04:00
    titleIE v6.0 Malformed PNG Image File Failure Vulnerability
    version67
  • accepted2014-02-24T04:03:22.562-05:00
    classvulnerability
    contributors
    • nameHarvey Rubinovitz
      organizationThe MITRE Corporation
    • nameMaria Mikhno
      organizationALTX-SOFT
    descriptionInternet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."
    familywindows
    idoval:org.mitre.oval:def:542
    statusaccepted
    submitted2004-01-27T12:00:00.000-04:00
    titleIE v5.5 Malformed PNG Image File Failure Vulnerability
    version66