Page 7 of 240 results (0.006 seconds)

CVSS: 9.3EPSS: 54%CPEs: 4EXPL: 0

13 Oct 2010 — Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a malformed record during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Parsing Vulnerability." Microsoft Word 2002 SP3 y 2003 SP3, Office 2004 para Mac, y Word Viewer no maneja adecuadamente un registro mal formado durante el análisis de un documento Word, lo que permite a atacantes remotos ejecutar código d... • http://www.us-cert.gov/cas/techalerts/TA10-285A.html • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 9.3EPSS: 60%CPEs: 4EXPL: 0

13 Oct 2010 — Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Excel Record Parsing Memory Corruption Vulnerability." Microsoft Excel 2002 SP3, Office 2004 y 2008 para Mac, y Open XML File Format Converter para Mac no valida correctamente la información de registro, lo cual permite a los atacantes remotos ejecutar código a su elección a t... • http://www.us-cert.gov/cas/techalerts/TA10-285A.html • CWE-20: Improper Input Validation •

CVSS: 9.3EPSS: 57%CPEs: 7EXPL: 0

13 Oct 2010 — Microsoft Excel 2003 SP3 and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Excel File Format Parsing Vulnerability." Microsoft Excel 2003 SP3 y 2007 SP2; Office 2004 y 2008 para Mac; Open XML File Format Converter para Mac; Excel Viewer SP2... • http://www.us-cert.gov/cas/techalerts/TA10-285A.html • CWE-20: Improper Input Validation •

CVSS: 9.3EPSS: 56%CPEs: 5EXPL: 0

13 Oct 2010 — Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out Of Bounds Array Vulnerability." Microsoft Excel 2002 SP3 y 2003 SP3, Office 2004 y 2008 para Mac, y Open XML File Format Converter para Mac no valida adecuadamente información de registro, que permite a atacantes remotos ejecutar código de su elección a través... • http://www.us-cert.gov/cas/techalerts/TA10-285A.html • CWE-20: Improper Input Validation •

CVSS: 9.3EPSS: 56%CPEs: 2EXPL: 0

13 Oct 2010 — Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Merge Cell Record Pointer Vulnerability." Microsoft Excel 2002 SP3 y Office 2004 para Mac no valida adecuadamente la información guardada, lo que ermite a atacantes remotos ejecutar código de su elección a través de documentos Excel manipulados, conocido como "Vulnerabilidad de registro de puntero Merge Cell." • http://www.us-cert.gov/cas/techalerts/TA10-285A.html • CWE-20: Improper Input Validation •

CVSS: 9.3EPSS: 56%CPEs: 3EXPL: 0

13 Oct 2010 — Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negative Future Function Vulnerability." Microsoft Excel 2002 SP3 y 2003 SP3, y Office 2004 para Mac, no valida adecuadamente la información en formato binario, lo que permite a atacantes remotos ejecutar código de su elección a través de documentos Excel manipulados, conocido como "Vulnerabilidad... • http://www.us-cert.gov/cas/techalerts/TA10-285A.html • CWE-20: Improper Input Validation •

CVSS: 9.3EPSS: 50%CPEs: 4EXPL: 0

13 Oct 2010 — Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out-of-Bounds Memory Write in Parsing Vulnerability." Microsoft Excel 2002 SP3, Office 2004 y 2008 para Mac, y Open XML File Format Converter para Mac no valida correctamente la información de formato de archivo binario, lo cual permite a los atacantes remotos ejec... • http://www.us-cert.gov/cas/techalerts/TA10-285A.html • CWE-20: Improper Input Validation •

CVSS: 9.3EPSS: 57%CPEs: 4EXPL: 0

13 Oct 2010 — Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Ghost Record Type Parsing Vulnerability." Microsoft Excel 2002 SP3, Office 2004 y 2008 para Mac, y Open XML File Format Converter para Mac no valida adecuadamente la información de registro, lo que permite a atacantes remotos ejecutar código de su elección a través de un docum... • http://www.us-cert.gov/cas/techalerts/TA10-285A.html • CWE-20: Improper Input Validation •

CVSS: 9.3EPSS: 28%CPEs: 17EXPL: 1

15 Sep 2010 — The Uniscribe (aka new Unicode Script Processor) implementation in USP10.DLL in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2, and Microsoft Office XP SP3, 2003 SP3, and 2007 SP2, does not properly validate tables associated with malformed OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) Office document, aka "Uniscribe Font Parsing Engine Memory Corruption Vulnerability." La implementación Uniscribe... • https://www.exploit-db.com/exploits/15158 • CWE-20: Improper Input Validation •

CVSS: 9.3EPSS: 47%CPEs: 8EXPL: 0

11 Aug 2010 — Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly handle unspecified properties in rich text data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RTF document, aka "Word RTF Parsing Engine Memory Corruption Vulnerability." Microsoft O... • http://www.us-cert.gov/cas/techalerts/TA10-222A.html • CWE-94: Improper Control of Generation of Code ('Code Injection') •