CVE-2002-0823

Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HTML Help ActiveX control (HHCtrl.ocx) with a long pathname in the Item parameter.

Scoring

CVSS base score
2.58
EPSS probability
64.56%
Published
2003-04-02
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs