Show filters
138 Total Results
Displaying 61-70 of 138
Sort by:
Attacker Value
Unknown

CVE-2008-3019

Disclosure Date: August 12, 2008 (last updated October 04, 2023)
Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of an Encapsulated PostScript (EPS) file, which allows remote attackers to execute arbitrary code via a crafted EPS file, aka the "Malformed EPS Filter Vulnerability."
0
Attacker Value
Unknown

CVE-2008-2463

Disclosure Date: July 07, 2008 (last updated October 04, 2023)
The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.
0
Attacker Value
Unknown

CVE-2008-1091

Disclosure Date: May 13, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via a Rich Text Format (.rtf) file with a malformed string that triggers a "memory calculation error" and a heap-based buffer overflow, aka "Object Parsing Vulnerability."
0
Attacker Value
Unknown

CVE-2008-1434

Disclosure Date: May 13, 2008 (last updated October 04, 2023)
Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) selectors, related to a "memory handling error" that triggers memory corruption.
0
Attacker Value
Unknown

CVE-2008-0119

Disclosure Date: May 13, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka "Publisher Object Handler Validation Vulnerability."
0
Attacker Value
Unknown

CVE-2008-1089

Disclosure Date: April 08, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka "Visio Object Header Vulnerability."
0
Attacker Value
Unknown

CVE-2008-1090

Disclosure Date: April 08, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a crafted .DXF file, aka "Visio Memory Validation Vulnerability."
0
Attacker Value
Unknown

CVE-2008-1354

Disclosure Date: March 17, 2008 (last updated October 04, 2023)
SQL injection vulnerability in MyIssuesView.asp in Advanced Data Solutions Virtual Support Office-XP (VSO-XP) allows remote attackers to execute arbitrary SQL commands via the Issue_ID parameter.
0
Attacker Value
Unknown

CVE-2008-0118

Disclosure Date: March 11, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an "allocation error," aka "Microsoft Office Memory Corruption Vulnerability."
0
Attacker Value
Unknown

CVE-2008-0110

Disclosure Date: March 11, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers to execute arbitrary code via a crafted mailto URI.
0