CVE-2007-3029
https://notcve.org/view.php?id=CVE-2007-3029
Unspecified vulnerability in Microsoft Excel 2002 SP3 and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file containing multiple active worksheets, which results in memory corruption. Vulnerabilidad sin especificar en el Microsoft Excel 2002 SP3 y 2003 SP2 permite a atacantes con la intervención del usuario ejecutar código de su elección a través de un fichero Excel mal formado que contiene múltiples hojas de trabajo activas, lo que provoca una corrupción de memoria. • http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html http://osvdb.org/35958 http://secunia.com/advisories/25995 http://www.securityfocus.com/bid/22555 http://www.securitytracker.com/id?1018352 http://www.us-cert.gov/cas/techalerts/TA07-191A.html http://www.vupen.com/english/advisories/2007/2478 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-036 https://exchange.xforce.ibmcloud.com/vulnerabilities/35215 https://oval.cisecurity.org/repo •
CVE-2007-3490 – Microsoft Excel 2000/2003 - Sheet Name (PoC)
https://notcve.org/view.php?id=CVE-2007-3490
Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to the sheet name, as demonstrated by 2670.xls. Vulnerabilidad no especificada en Microsoft Excel 2003 SP2 permite a atacantes remotos tener impacto desconocido mediante vectores no especificados, posiblemente relacionado con el nombre de la hoja, como ha sido demostrado por 2670.xls. • https://www.exploit-db.com/exploits/4121 http://osvdb.org/38954 http://pstgroup.blogspot.com/2007/06/exploitmicrosoft-excel-20002003-sheet.html http://www.milw0rm.com/sploits/06272007-2670.zip http://www.securityfocus.com/bid/24691 http://www.securitytracker.com/id?1018321 https://exchange.xforce.ibmcloud.com/vulnerabilities/35132 •
CVE-2007-1214
https://notcve.org/view.php?id=CVE-2007-1214
Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted AutoFilter filter record in an Excel BIFF8 format XLS file, which triggers memory corruption. Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer y 2004 para Mac, permite a los atacantes remotos asistidos por el usuario ejecutar código arbitrario por medio de un registro de filtro de AutoFilter creado en un archivo XLS de formato BIFF8 de Excel, lo que desencadena corrupción de memoria . • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=527 http://secunia.com/advisories/25150 http://www.kb.cert.org/vuls/id/253825 http://www.osvdb.org/34395 http://www.securityfocus.com/archive/1/468871/100/200/threaded http://www.securityfocus.com/bid/23780 http://www.securitytracker.com/id?1018012 http://www.us-cert.gov/cas/techalerts/TA07-128A.html http://www.vupen.com/english/advisories/2007/1708 https://docs.microsoft.com/en-us/security-updates • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2007-1203
https://notcve.org/view.php?id=CVE-2007-1203
Unspecified vulnerability in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a crafted set font value in an Excel file, which results in memory corruption. Vulnerabilidad no especificada en Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, 2004 para Mac, y 2007 permite a atacantes remotos con la intervención del usuario ejecutar código de su elección mediante un valor de selección de fuente manipulado en un archivo Excel, lo cual resulta en corrupción de memoria. • http://secunia.com/advisories/25150 http://www.osvdb.org/34394 http://www.securityfocus.com/archive/1/468871/100/200/threaded http://www.securityfocus.com/bid/23779 http://www.securitytracker.com/id?1018012 http://www.us-cert.gov/cas/techalerts/TA07-128A.html http://www.vupen.com/english/advisories/2007/1708 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-023 https://exchange.xforce.ibmcloud.com/vulnerabilities/33914 https://oval.cisecurity.org/re •
CVE-2007-0215 – Microsoft Excel BIFF File Format Named Graph Record Parsing Stack Overflow Vulnerability
https://notcve.org/view.php?id=CVE-2007-0215
Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption. Un desbordamiento de búfer en la región stack de la memoria en Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 y 2003 Viewer permite a los atacantes remotos asistidos por el usuario ejecutar código arbitrario por medio de un archivo BIFF .XLS con un registro de gráfico con nombre inapropiado, lo que resulta en corrupción de memoria. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office Excel. Exploitation requires that the attacker coerce the target into opening a malicious .XLS file. The specific flaw exists within the parsing of the BIFF file format used by Microsoft Excel. During the processing of a malformed Named Graph record, user-supplied data may be copied to the stack unchecked thereby leading to an exploitable stack-based buffer overflow. • http://secunia.com/advisories/25150 http://www.osvdb.org/34393 http://www.securityfocus.com/archive/1/467988/100/0/threaded http://www.securityfocus.com/archive/1/468871/100/200/threaded http://www.securityfocus.com/bid/23760 http://www.securitytracker.com/id?1018012 http://www.us-cert.gov/cas/techalerts/TA07-128A.html http://www.vupen.com/english/advisories/2007/1708 http://www.zerodayinitiative.com/advisories/ZDI-07-026.html https://docs.microsoft.com/en-us/securit •