Show filters
138 Total Results
Displaying 61-70 of 138
Sort by:
Attacker Value
Unknown
CVE-2008-3019
Disclosure Date: August 12, 2008 (last updated October 04, 2023)
Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of an Encapsulated PostScript (EPS) file, which allows remote attackers to execute arbitrary code via a crafted EPS file, aka the "Malformed EPS Filter Vulnerability."
0
Attacker Value
Unknown
CVE-2008-2463
Disclosure Date: July 07, 2008 (last updated October 04, 2023)
The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.
0
Attacker Value
Unknown
CVE-2008-1091
Disclosure Date: May 13, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via a Rich Text Format (.rtf) file with a malformed string that triggers a "memory calculation error" and a heap-based buffer overflow, aka "Object Parsing Vulnerability."
0
Attacker Value
Unknown
CVE-2008-1434
Disclosure Date: May 13, 2008 (last updated October 04, 2023)
Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) selectors, related to a "memory handling error" that triggers memory corruption.
0
Attacker Value
Unknown
CVE-2008-0119
Disclosure Date: May 13, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka "Publisher Object Handler Validation Vulnerability."
0
Attacker Value
Unknown
CVE-2008-1089
Disclosure Date: April 08, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka "Visio Object Header Vulnerability."
0
Attacker Value
Unknown
CVE-2008-1090
Disclosure Date: April 08, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a crafted .DXF file, aka "Visio Memory Validation Vulnerability."
0
Attacker Value
Unknown
CVE-2008-1354
Disclosure Date: March 17, 2008 (last updated October 04, 2023)
SQL injection vulnerability in MyIssuesView.asp in Advanced Data Solutions Virtual Support Office-XP (VSO-XP) allows remote attackers to execute arbitrary SQL commands via the Issue_ID parameter.
0
Attacker Value
Unknown
CVE-2008-0118
Disclosure Date: March 11, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an "allocation error," aka "Microsoft Office Memory Corruption Vulnerability."
0
Attacker Value
Unknown
CVE-2008-0110
Disclosure Date: March 11, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers to execute arbitrary code via a crafted mailto URI.
0