Vulnerabilities > CVE-2003-0010 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 46 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS03-008.NASL |
description | The remote host is vulnerable to a flaw in the Windows Script Engine, that provides Windows with the ability to execute script code. To exploit this flaw, an attacker would need to lure one user on this host to visit a rogue website or to send a user an HTML email with a malicious code in it. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11423 |
published | 2003-03-20 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11423 |
title | MS03-008: Flaw in Windows Script Engine (814078) |
code |
|
Oval
accepted 2011-01-31T04:00:13.534-05:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name Matthew Wojcik organization The MITRE Corporation name Anna Min organization BigFix, Inc name Nate Przybyszewski organization The MITRE Corporation
description Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack. family windows id oval:org.mitre.oval:def:134 status accepted submitted 2004-11-02T12:00:00.000-04:00 title Windows Script Engine Heap Overflow (Test 4) version 68 accepted 2007-03-21T16:17:10.592-04:00 class vulnerability contributors name Tiffany Bergeron organization The MITRE Corporation name David Proulx organization The MITRE Corporation name David Proulx organization The MITRE Corporation name Christine Walzer organization The MITRE Corporation name Christine Walzer organization The MITRE Corporation name Matthew Wojcik organization The MITRE Corporation name Anna Min organization BigFix, Inc name Nate Przybyszewski organization The MITRE Corporation name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack. family windows id oval:org.mitre.oval:def:200 status deprecated submitted 2003-08-27T12:00:00.000-04:00 title DEPRECATED: Windows Script Engine Heap Overflow (Test 1) version 70 accepted 2007-03-21T16:17:27.797-04:00 class vulnerability contributors name Tiffany Bergeron organization The MITRE Corporation name David Proulx organization The MITRE Corporation name Christine Walzer organization The MITRE Corporation name Matthew Wojcik organization The MITRE Corporation name Anna Min organization BigFix, Inc name Nate Przybyszewski organization The MITRE Corporation name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack. family windows id oval:org.mitre.oval:def:794 status deprecated submitted 2004-03-03T12:00:00.000-04:00 title DEPRECATED: Windows Script Engine Heap Overflow (Test 2) version 70 accepted 2007-03-21T16:17:28.063-04:00 class vulnerability contributors name Tiffany Bergeron organization The MITRE Corporation name David Proulx organization The MITRE Corporation name Christine Walzer organization The MITRE Corporation name Matthew Wojcik organization The MITRE Corporation name Anna Min organization BigFix, Inc name Nate Przybyszewski organization The MITRE Corporation name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack. family windows id oval:org.mitre.oval:def:795 status deprecated submitted 2004-03-03T12:00:00.000-04:00 title DEPRECATED: Windows Script Engine Heap Overflow (Test 3) version 70
References
- http://www.securityfocus.com/bid/7146
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0139.html
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=26
- http://marc.info/?l=bugtraq&m=104812108307645&w=2
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A795
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A794
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A200
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A134
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-008