[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2003-0820Date: (C)2003-12-15   (M)2023-12-22


Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://archives.neohapsis.com/archives/bugtraq/2003-10/0163.html
BID-8835
MS03-050
http://www.security.nnov.ru/search/document.asp?docid=5243
word-macro-execute-code(13682)

CPE    22
cpe:/a:microsoft:word:97:::zh
cpe:/a:microsoft:word:97:::ko
cpe:/a:microsoft:word:2000:::ja
cpe:/a:microsoft:word:2002:sp2
...
OVAL    4
oval:org.mitre.oval:def:336
oval:org.mitre.oval:def:585
oval:org.mitre.oval:def:586
oval:org.mitre.oval:def:668
...

© SecPod Technologies