CVE-2004-1049
5.1
CVSS v2.0 Base Score
63.01%
MEDIUM RiskEPSS (98th percentile)
NVD-CWE-Other
Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."
Published: 12/31/2004
Modified: 4/16/2026
Vulnerability Summary
CVSS v2 Score
5.1
AV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS Score (Exploitation Probability)
63.01%MEDIUM Exploitation Risk
98th percentile
This vulnerability has a 63.01% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.
CWE Classification
NVD-CWE-Other