This page lists publicly disclosed CVE vulnerabilities affecting microsoft html_help_workshop (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2009-0133 | Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564. | [email protected] | 10.0 | 76.10% | 2009-01-15 | 2026-04-23 |
| CVE-2007-0427 | Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section. | [email protected] | 9.3 | 55.26% | 2007-01-23 | 2026-04-23 |
| CVE-2007-0352 | Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt file composed of lines that begin with an integer followed by a space and a long string. | [email protected] | 9.3 | 67.51% | 2007-01-19 | 2026-04-23 |
| CVE-2006-0564 | Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file field. | [email protected] | 7.5 | 82.71% | 2006-02-06 | 2026-04-16 |