CVE-2010-0822 – Microsoft Excel - Malformed OBJ Record Handling Overflow (MS11-038)
https://notcve.org/view.php?id=CVE-2010-0822
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted OBJ (0x5D) record, aka "Excel Object Stack Overflow Vulnerability." Microsoft Office Excel 2002 SP3, Office 2004 para Mac, Office 2008 para Mac, y el Conversor de Formatos de Ficheros Open XML -Open XML File Format Converter- para Mac, permite a atacantes remotos ejecutar código a su elección a través de archivos manipulados de Excel, también conocido como "Vulnerabilidad de desbordamiento de pila de objetos Excel". • https://www.exploit-db.com/exploits/18143 https://www.exploit-db.com/exploits/15094 https://www.exploit-db.com/exploits/14361 http://osvdb.org/65236 http://www.securityfocus.com/archive/1/511752/100/0/threaded http://www.securityfocus.com/bid/40520 http://www.us-cert.gov/cas/techalerts/TA10-159B.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-038 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7265 htt • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2010-0823
https://notcve.org/view.php?id=CVE-2010-0823
Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-1247 and CVE-2010-1249. Vulnerabilidad no especificada en Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 y SP2; Office 2004 para mac; Office 2008 para Mac; Open XML File Format Converter para Mac; Office Excel Viewer SP1 y SP2; y Office Compatibility Pack para Word, Excel, y PowerPoint 2007 File Formats SP1 y SP2; permite a atacantes remotos ejecutar código de su elección a través de un fichero Excel manipulado, conocido como "Vulnerabilidad de corrupción de memoria Excel", una vulnerabilidad diferente que CVE-2010-1247 y CVE-2010-1249. • http://osvdb.org/65233 http://www.us-cert.gov/cas/techalerts/TA10-159B.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-038 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7240 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2010-0824 – Microsoft Excel - WOPT Record Parsing Heap Memory Corruption
https://notcve.org/view.php?id=CVE-2010-0824
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed WOPT (0x80B) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0821 and CVE-2010-1245. Vulnerabilidad no especificada en Microsoft Office Excel 2002 SP3 y Office 2004 para Mac permite a atacantes remotos ejecutar código a su elección a través de archivos de Excel manipulados, también conocido como "Vulnerabilidad de corrupción de registro de memoria Excel" una vulnerabilidad diferente que CVE-2010-0821 y CVE-2010-1245. • https://www.exploit-db.com/exploits/15065 http://www.securityfocus.com/archive/1/511760/100/0/threaded http://www.securityfocus.com/bid/40522 http://www.us-cert.gov/cas/techalerts/TA10-159B.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-038 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6768 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2010-1246 – Excel RTD - Memory Corruption
https://notcve.org/view.php?id=CVE-2010-1246
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record, aka "Excel RTD Memory Corruption Vulnerability." Vulnerabilida no especificada en Microsoft Office Excel 2002 SP3 permite a atacantes remotos ejecutar código de su elección a través de un fichero Excel manipulado, conocido como "Vulnerabilidad de corrupción de memoria RTD para Excel" • https://www.exploit-db.com/exploits/14966 http://www.securityfocus.com/archive/1/511755/100/0/threaded http://www.us-cert.gov/cas/techalerts/TA10-159B.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-038 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6839 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2010-1247 – Excel RTD - Memory Corruption
https://notcve.org/view.php?id=CVE-2010-1247
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record that triggers heap corruption, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1249. Vulnerabilidad no especificada en Microsoft Office Excel 2002 SP3 permite a atacantes remotos ejecutar código de su elección a través de un fichero Excel manipulado, conocido como "Vulnerabilidad corrupción de memoria Excel", una vulnerabilidad diferente que CVE-2010-0823 y CVE-2010-1249. • https://www.exploit-db.com/exploits/14966 http://osvdb.org/65237 http://www.securityfocus.com/archive/1/511754/100/0/threaded http://www.us-cert.gov/cas/techalerts/TA10-159B.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-038 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6630 • CWE-94: Improper Control of Generation of Code ('Code Injection') •