CVE-2006-2376
Integer overflow in the PolyPolygon function in Graphics Rendering Engine on Microsoft Windows 98 and Me allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) or EMF image with a sum of entries in the vertext counts array and number of polygons that triggers a heap-based buffer overflow.
Date published : 2006-06-13
http://www.securityfocus.com/bid/18322
http://www.securityfocus.com/archive/1/436950/100/0/threaded