Back

CVE-2004-0201

Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.

Published: Aug 6, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (54)

Vendor Product Version
avaya ip600_media_servers *
avaya definity_one_media_server *
avaya s8100 *
avaya modular_messaging_message_storage_server s3400
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2000 *
microsoft windows_2003_server enterprise
microsoft windows_2003_server enterprise_64-bit
microsoft windows_2003_server r2
microsoft windows_2003_server r2
microsoft windows_2003_server standard
microsoft windows_2003_server web
microsoft windows_98 *
microsoft windows_98se *
microsoft windows_me *
microsoft windows_nt 4.0
microsoft windows_nt 4.0

…and 34 more

GitHub Security Advisory GHSA-rfqx-p859-5rqq

Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 45.31%

Top 1% most likely to be exploited

Threat Score 53.6 / 100

Data Sources

NVD EPSS GitHub