Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a crafted .hlp file.
- http://marc.info/?l=bugtraq&m=110383690219440&w=2
- https://github.com/ARPSyndicate/cve-scores