An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."
| Software | From | Fixed in |
|---|---|---|
| microsoft / windows_98se | - | - |
| microsoft / windows_xp | - | - |
| microsoft / windows_2003_server | sp1 | sp1.x |
| microsoft / windows_2003_server | r2 | r2.x |
| microsoft / windows_me | - | - |
| microsoft / windows_2000 | - | - |
| microsoft / windows_98 | - | - |