Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba
Published Oct 16, 2004
10.0
HIGHCVSS 2.0
EPSS 46.98%
Description
Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.
Affected products
No data.
Configuration 1
- 6.0.2900
Configuration 2
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (21 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 46.98% (0.46978) | 98.80th | v5 (v2026.06.15) |
| Jul 20, 2026 | 46.98% (0.46978) | 98.70th | v5 (v2026.06.15) |
| Jun 20, 2026 | 51.01% (0.51011) | 98.79th | v5 (v2026.06.15) |
| Jun 15, 2026 | 46.98% (0.46978) | 98.68th | v5 (v2026.06.15) |
| Jan 11, 2026 | 78.25% (0.78254) | 98.97th | v4 (v2025.03.14) |
| Dec 28, 2025 | 76.66% (0.76660) | 98.90th | v4 (v2025.03.14) |
| Dec 27, 2025 | 73.83% (0.73831) | 98.78th | v4 (v2025.03.14) |
| Oct 28, 2025 | 76.66% (0.76660) | 98.89th | v4 (v2025.03.14) |
| Oct 27, 2025 | 73.83% (0.73831) | 98.76th | v4 (v2025.03.14) |
| Oct 23, 2025 | 76.66% (0.76660) | 98.89th | v4 (v2025.03.14) |
| Oct 1, 2025 | 84.18% (0.84178) | 99.28th | v4 (v2025.03.14) |
| Mar 30, 2025 | 74.75% (0.74753) | 98.79th | v4 (v2025.03.14) |
| Mar 29, 2025 | 67.62% (0.67615) | 98.04th | v4 (v2025.03.14) |
| Mar 19, 2025 | 74.75% (0.74753) | 98.78th | v4 (v2025.03.14) |
| Mar 17, 2025 | 76.09% (0.76094) | 98.86th | v4 (v2025.03.14) |
| Dec 12, 2024 | 96.40% (0.96397) | 99.63th | v3 (v2023.03.01) |
| Apr 23, 2024 | 96.28% (0.96278) | 99.51th | v3 (v2023.03.01) |
| Sep 23, 2023 | 95.99% (0.95990) | 99.27th | v3 (v2023.03.01) |
| Mar 7, 2023 | 96.34% (0.96341) | 99.20th | v3 (v2023.03.01) |
| Mar 6, 2023 | 56.06% (0.56056) | 98.82th | v2 (v2022.01.01) |
| Feb 4, 2022 | 56.06% (0.56056) | 98.48th | v2 (v2022.01.01) |
No CWE recorded.
References (17)
- http://seclists.org/lists/bugtraq/2004/Apr/0322.html mailing-listx_refsource_BUGTRAQVendor Advisory
- http://seclists.org/lists/fulldisclosure/2004/Apr/0933.html mailing-listx_refsource_FULLDISCVendor Advisory
- http://secunia.com/advisories/11482/ third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1011647 vdb-entryx_refsource_SECTRACK
- http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B322857 vendor-advisoryx_refsource_MSKB
- http://www.kb.cert.org/vuls/id/616200 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.osvdb.org/5687 vdb-entryx_refsource_OSVDB
- http://www.securiteam.com/windowsntfocus/5JP0M1PCKI.html x_refsource_MISC
- http://www.securityfocus.com/bid/10213 vdb-entryx_refsource_BID
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-037 vendor-advisoryx_refsource_MS
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15956 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17662 vdb-entryx_refsource_XF
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1601 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1749 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2638 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4345 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5307 vdb-entrysignaturex_refsource_OVAL
Change history (0)
No recorded changes yet.