Back

CVE-2003-1048

HIGH

Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.

Published: Jul 27, 2004 Modified: Apr 16, 2026
CWE-415

CVSS Metrics

CVSSv3
Attack Vector: LOCAL Attack Complexity: LOW Privileges Required: NONE User Interaction: REQUIRED Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products (18)

Vendor Product Version
microsoft internet_explorer 5.01
microsoft internet_explorer 5.01
microsoft internet_explorer 5.01
microsoft internet_explorer 5.5
microsoft internet_explorer 6.0
microsoft internet_explorer 6.0
microsoft outlook 2000
microsoft outlook 2000
microsoft outlook 2000
microsoft windows_98 -
microsoft windows_98se -
microsoft windows_me -
microsoft windows_nt 4.0
microsoft windows_nt 4.0
microsoft windows_nt 4.0
microsoft windows_server_2003 -
microsoft windows_xp -
microsoft windows_xp -

GitHub Security Advisory GHSA-9c7h-3j4x-5hw6

Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows...

Risk Scores

CVSS Score 7.8 / 10
EPSS Score 33.17%

Top 3% most likely to be exploited

Threat Score 41.2 / 100

Data Sources

NVD EPSS GitHub