Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.
2003-08-27T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | directx | 5.2 | Yes |
Application | microsoft | directx | 6.1 | Yes |
Application | microsoft | directx | 7.0 | Yes |
Application | microsoft | directx | 7.0a | Yes |
Application | microsoft | directx | 8.1 | Yes |
Application | microsoft | directx | 9.0a | Yes |