VDB
CVE-2004-1305
CVE-2004-1305
PUBLISHED
CVSS 5 MEDIUM
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.
EPSS 78.47% · 99.1th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
78.47%
99.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| nortel | ip_softphone_2050 | |
| microsoft | windows_2003_server | enterprise, r2, enterprise_64-bit |
| microsoft | windows_2000 | |
| nortel | symposium_agent | |
| microsoft | windows_nt | 4.0, 4.0, 4.0 |
| nortel | periphonics | |
| nortel | media_communication_server_5200 | 3.0 |
| nortel | media_processing_server | |
| nortel | symposium_call_center_server | |
| nortel | media_communication_server_5100 | 3.0 |
| nortel | symposium_tapi_service_provider | |
| microsoft | windows_me | |
| nortel | symposium_web_centre_portal | |
| microsoft | windows_xp | |
| microsoft | windows_98 | |
| microsoft | windows_98se | |
| nortel | symposium_network_control_center | |
| n/a | n/a | n/a |
| nortel | symposium_web_client | |
| nortel | symposium_express_call_center |
Timeline
- Dec 23, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Dec 14, 2023 EPSS Score
- Feb 13, 2024 EPSS Score
References
- oval:org.mitre.oval:def:712 vdb
- oval:org.mitre.oval:def:2580 vdb
- VU#697136 third-party-advisory
- MS05-002 vendor-advisory
- http://www.xfocus.net/flashsky/icoExp/ url
- oval:org.mitre.oval:def:3216 vdb
- 20041223 Microsoft Windows Kernel ANI File Parsing Crash and DOS Vulnerability mailing-list
- win-ani-ratenumber-dos(18667) vdb
- TA05-012A third-party-advisory
- VU#177584 third-party-advisory
- oval:org.mitre.oval:def:1304 vdb
- oval:org.mitre.oval:def:3957 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2004-1305 advisory
- http://www.xfocus.net/flashsky/icoExp url