VYPR

Windows Help

by Microsoft

CVEs (2)

  • CVE-2002-0823Aug 12, 2002
    risk 0.05cvss —epss 0.26

    Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HTML Help ActiveX control (HHCtrl.ocx) with a long pathname in the Item parameter.

  • CVE-2006-1591Apr 3, 2006
    risk 0.01cvss —epss 0.07

    Heap-based buffer overflow in Microsoft Windows Help winhlp32.exe allows user-assisted attackers to execute arbitrary code via crafted embedded image data in a .hlp file.