
CVE-2010-0260
https://notcve.org/view.php?id=CVE-2010-0260
10 Mar 2010 — Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXTUPLE record is broken up into several records," aka "Microsoft Office Excel MDXTUPLE Record Heap Overflow Vulnerability." Desbordamiento de búfer basado en memoria dinámica en Microsoft Office Excel 2007 SP1 y SP2; Office Ex... • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=862 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2010-0261
https://notcve.org/view.php?id=CVE-2010-0261
10 Mar 2010 — Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSET record is broken up into several records," aka "Microsoft Office Excel MDXSET Record Heap Overflow Vulnerability." Desbordamiento de búfer basado en memoria dinámica (heap) en Microsoft Office Excel v2007 SP1 y SP2 y Office Compatibility Pack para Word, E... • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=861 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2010-0262
https://notcve.org/view.php?id=CVE-2010-0262
10 Mar 2010 — Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an uninitialized stack variable, aka "Microsoft Office Excel FNGROUPNAME Record Uninitialized Memory Vulnerability." Microsoft Office Excel 2007 SP1 y SP2 y Office 2004 para Mac no analiza correctamente el formato de archivo Excel, lo cual permite a atacantes remotos ejecutar código a su elección... • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=860 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2010-0264
https://notcve.org/view.php?id=CVE-2010-0264
10 Mar 2010 — Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability." Microsoft Office Excel 2002 SP3, Office 2004 y 2008 para Mac y el Conversor de Formatos de Ficheros Open XML -Open XML File Format Converter- para Mac, no analizan adecuadamente los formatos de fichero Exce... • http://www.securitytracker.com/id?1023698 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2010-0263 – Microsoft Office Excel XLSX File Parsing Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2010-0263
09 Mar 2010 — Microsoft Office Excel 2007 SP1 and SP2; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; and Office SharePoint Server 2007 SP1 and SP2 do not validate ZIP headers during decompression of Open XML (.XLSX) documents, which allows remote attackers to execute arbitrary code via a crafted document that triggers access to uninitialized memory locations, aka "Microsoft Office Excel... • http://www.securityfocus.com/archive/1/509979/100/0/threaded • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2010-0031
https://notcve.org/view.php?id=CVE-2010-0031
10 Feb 2010 — Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint OEPlaceholderAtom 'placementId' Invalid Array Indexing Vulnerability." Error de indexación en Microsoft Office PowerPoint 2002 SP3 y 2003 SP3, y PowerPoint en Office 2004 para Mac, permite a atacantes remotos ejecutar código de su elección a través de un documento powerpoint modificado. También cono... • http://www.securitytracker.com/id?1023563 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2009-2506
https://notcve.org/view.php?id=CVE-2009-2506
09 Dec 2009 — Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a DOC file with an invalid number of property names in the DocumentSummaryInformation stream, which triggers a heap-based buffer overflow. Desbordamiento de enteros en los convertidores de texto en Microsoft Office Word 2002 SP3 y 2003 SP3; Works versión 8.5; Office ... • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=834 • CWE-189: Numeric Errors •

CVE-2009-0102
https://notcve.org/view.php?id=CVE-2009-0102
09 Dec 2009 — Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability." Microsoft Project 2000 SR1 y 2002 SP1 y Office Project 2003 SP3 no maneja de manera apropiada la reserva de memoria para ficheros Project, lo que permite a atacantes remotos ejecutar código de su elección mediante un fichero manipulado. También conocido c... • http://www.us-cert.gov/cas/techalerts/TA09-342A.html • CWE-399: Resource Management Errors •

CVE-2009-3130
https://notcve.org/view.php?id=CVE-2009-3130
11 Nov 2009 — Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a spreadsheet containing a malformed Binary File Format (aka BIFF) record that triggers memory corruption, aka "Excel Document Parsing Heap Overflow Vulnerability." Desbordamiento de búfer basado en memoria dinámica en Microsoft Office Excel v2002 SP3, Office v2004 y v2008 para Mac, y Open XML File Format Converter para ... • http://www.securitytracker.com/id?1023157 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2009-3131
https://notcve.org/view.php?id=CVE-2009-3131
11 Nov 2009 — Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a spreadsheet with a crafted formula embedded in a cell, aka "Excel Formula Parsing Memory Corruption Vulnerability." Microsoft Office Excel v2002 SP3, v2003 SP3, y 2007... • http://www.securitytracker.com/id?1023157 • CWE-94: Improper Control of Generation of Code ('Code Injection') •