CVE-2004-1922
Last modified
CVE-2004-1922 is a vulnerability of currently unknown severity. Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a large memory size.. EPSS estimates a 6.79% chance of exploitation in the next 30 days.
Description
Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a large memory size.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Internet Explorer | 5.5 |
| Microsoft | Internet Explorer | 6.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1922?
How severe is CVE-2004-1922?
How do I fix CVE-2004-1922?
Are you affected by CVE-2004-1922?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
