Skip to main content

CVE-2004-1049

5.1
CVSS v2.0 Base Score
63.01%
MEDIUM RiskEPSS (98th percentile)
NVD-CWE-Other

Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."

Published: 12/31/2004
Modified: 4/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

5.1

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

63.01%MEDIUM Exploitation Risk
98th percentile

This vulnerability has a 63.01% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.

CWE Classification

NVD-CWE-Other