VYPR
High severity7.8NVD Advisory· Published Jul 27, 2004· Updated Apr 16, 2026

CVE-2003-1048

CVE-2003-1048

Description

Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.

Affected products

18
  • cpe:2.3:a:microsoft:internet_explorer:5.01:sp2:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:microsoft:internet_explorer:5.01:sp2:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:5.01:sp3:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:5.01:sp4:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:5.5:sp2:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:6.0:-:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:6.0:sp1:*:*:*:*:*:*
  • Microsoft/Outlook3 versions
    cpe:2.3:a:microsoft:outlook:2000:sp2:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:microsoft:outlook:2000:sp2:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:outlook:2000:sp3:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:outlook:2000:sp4:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_98:-:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_98se:-:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_me:-:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:*:*:server:*:*:*+ 2 more
    • cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:*:*:server:*:*:*
    • cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:*:*:workstation:*:*:*
    • cpe:2.3:o:microsoft:windows_nt:4.0:sp6:*:*:terminal_server:*:*:*
  • cpe:2.3:o:microsoft:windows_server_2003:-:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_xp:-:sp1:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

16

News mentions

0

No linked articles in our index yet.