Back
CVE-2004-0201
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
Published: Aug 6, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (54)
| Vendor | Product | Version |
|---|---|---|
| avaya | ip600_media_servers | * |
| avaya | definity_one_media_server | * |
| avaya | s8100 | * |
| avaya | modular_messaging_message_storage_server | s3400 |
| microsoft | windows_2000 | * |
| microsoft | windows_2000 | * |
| microsoft | windows_2000 | * |
| microsoft | windows_2000 | * |
| microsoft | windows_2000 | * |
| microsoft | windows_2003_server | enterprise |
| microsoft | windows_2003_server | enterprise_64-bit |
| microsoft | windows_2003_server | r2 |
| microsoft | windows_2003_server | r2 |
| microsoft | windows_2003_server | standard |
| microsoft | windows_2003_server | web |
| microsoft | windows_98 | * |
| microsoft | windows_98se | * |
| microsoft | windows_me | * |
| microsoft | windows_nt | 4.0 |
| microsoft | windows_nt | 4.0 |
…and 34 more
GitHub Security Advisory GHSA-rfqx-p859-5rqq
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98...
References (18)
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023919.html
- http://www.kb.cert.org/vuls/id/920060 Patch, Third Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-196A.html Patch, Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-023
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16586
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1503
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1530
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2155
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3179
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023919.html
- http://www.kb.cert.org/vuls/id/920060 Patch, Third Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-196A.html Patch, Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-023
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16586
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1503
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
45.31%
Top 1% most likely to be exploited
Threat Score
53.6 / 100
Data Sources
NVD
EPSS
GitHub