Microsoft Vulnerabilities and Situations for 2007 in sgpkg-ips-318-4219
Vulnerabilities
MS07-069 Internet-Explorer-DOM-Object-Cache-Management-Memory-Corruption
| About this vulnerability: | A vulnerability in Microsoft Internet Explorer | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-138-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Internet Explorer 6.0; Internet Explorer 7.0 | ||||
| Type: | Malfunction | ||||
| Description: | There is a memory corruption vulnerability in Microsoft Internet Explorer. The vulnerability is due to the way Internet Explorer handles uninitialized or removed objects. Remote attackers can exploit this vulnerability by persuading target users to visit a specially crafted web page. Successful exploitation may allow the attacker to execute arbitrary code on the vulnerable client system, in the context of the logged in user. | ||||
| Situation |
HTTP_SS-Internet-Explorer-DOM-Object-Cache-Management-Memory-Corruption
|
||||
| References: |
|
MS07-069 Microsoft-Internet-Explorer-DHTML-Objects-Memory-Corruption
| About this vulnerability: | A memory corruption vulnerability in Microsoft Internet Explorer | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-136-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Internet Explorer | ||||
| Type: | Malfunction | ||||
| Description: | There is a memory corruption vulnerability in Microsoft Internet Explorer. The vulnerability is due to the way Internet Explorer handles the switching of page location. Remote attackers can exploit this vulnerability by persuading target users to visit a specially crafted web page. Successful exploitation may allow the attacker to execute arbitrary code on the vulnerable client system in the context of the logged in user. | ||||
| Situation |
HTTP_SS-Microsoft-Internet-Explorer-DHTML-Objects-Memory-Corruption
|
||||
| References: |
|
MS07-069 Microsoft-Internet-Explorer-Object-Reference-Counting-Memory-Corruption
| About this vulnerability: | A memory corruption vulnerability in Microsoft Internet Explorer | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-134-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Internet Explorer | ||||
| Type: | Malfunction | ||||
| Description: | There is a memory corruption vulnerability Microsoft Internet Explorer. Internet Explorer incorrectly handles initialized or removed objects, causing memory corruption. Remote attackers can exploit this vulnerability by persuading target users to visit a specially crafted web page. Successful exploitation may allow the attacker to execute arbitrary code on the vulnerable client system, in the context of the logged in user. | ||||
| Situation |
HTTP_SS-Microsoft-Internet-Explorer-Object-Reference-Counting-Memory-Corruption
|
||||
| References: |
|
MS07-068 Microsoft-Windows-Media-Format-ASF-Parsing-Code-Execution
| About this vulnerability: | A vulnerability in Microsoft Windows Media Format Runtime | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-136-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Windows Media Format Runtime; Windows Media Format Runtime x64 Edition; Windows Media Services | ||||
| Type: | Buffer Overflow | ||||
| Description: | There are multiple buffer overflow vulnerabilities in the Microsoft Windows Media Format processing engine. These vulnerabilities are caused by a boundary error when processing Advanced Systems Format (ASF) files. A remote attacker can exploit this vulnerability by enticing the target user to open a crafted ASF file, potentially causing arbitrary code to be injected and executed in the security context of the currently logged in user. | ||||
| Situation |
HTTP_SS-Microsoft-Windows-Media-Format-ASF-Parsing-Code-Execution-JPEG
|
||||
| Situation |
HTTP_SS-Microsoft-Windows-Media-Format-ASF-Parsing-Code-Execution-Sum
|
||||
| Situation |
HTTP_SS-Microsoft-Windows-Media-Format-ASF-Parsing-Code-Execution-Spread
|
||||
| Situation |
HTTP_SS-Microsoft-Windows-Media-Format-ASF-Parsing-Code-Execution-Sig
|
||||
| References: |
|
MS07-065 MSRPC-Message-Queuing-Service-Queue-Name-String-Buffer-Overflow
| About this vulnerability: | A buffer overflow in the Microsoft Message Queuing Service | ||||
| Risk: | Moderate | ||||
| First detected in: | sgpkg-ips-133-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows 2000 SP4;Windows XP SP2;Windows 2000 Server | ||||
| Software: | <os> | ||||
| Type: | Buffer Overflow | ||||
| Description: | Microsoft Message Queuing (MSMQ) Service suffers from a buffer overflow vulnerability in the handling of long queue names. Remote attackers can exploit the vulnerability via an unauthenticated MSRPC request containing a malicious message queue name, and potentially execute arbitrary code on the vulnerable host. | ||||
| Situation |
MSRPC-TCP_CPS-Message-Queuing-Service-Queue-Name-String-Buffer-Overflow
|
||||
| References: |
|
MS07-064 Microsoft-DirectX-Sami-File-Parsing-Code-Execution
| About this vulnerability: | A buffer overflow vulnerability in Microsoft DirectX | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-136-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows 2000 | ||||
| Software: | DirectX | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a buffer overflow vulnerability in the Microsoft DirectX application framework. The vulnerability is due to the way certain DirectX libraries handle specially crafted Synchronized Accessible Media Interchange (SAMI) files. A remote attacker could exploit this vulnerability by persuading a user to open a specially crafted SAMI file, potentially causing arbitrary code to be injected and executed in the security context of the logged in user. | ||||
| Situation |
HTTP_SS-Microsoft-DirectX-Sami-File-Parsing-Code-Execution
|
||||
| References: |
|
MS07-064 Microsoft-DirectX-WAV-And-AVI-File-Parsing-Code-Execution
| About this vulnerability: | A vulnerability in Microsoft DirectX | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-134-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows 2000; Windows XP; Windows Vista; Windows 2003 | ||||
| Software: | <os> | ||||
| Type: | Integer Overflow | ||||
| Description: | There is a buffer overflow vulnerability in the Microsoft DirectX application framework. The vulnerability is due to the way certain DirectX libraries handle specially crafted WAV and AVI files. A remote attacker could exploit this vulnerability by persuading a user to open a specially crafted WAV or AVI file, potentially causing arbitrary code to be injected and executed in the security context of the logged in user. | ||||
| Situation |
HTTP_SS-Microsoft-DirectX-WAV-And-AVI-File-Parsing-Code-Execution
|
||||
| References: |
|
MS07-061 Microsoft-Windows-ShellExecute-And-IE7-Url-Handling-Code-Execution
| About this vulnerability: | A vulnerability in URL protocol handlers of Microsoft Windows | ||||
| Risk: | Moderate | ||||
| First detected in: | sgpkg-ips-125-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows XP; Windows 2003 | ||||
| Software: | Adobe Acrobat; Adobe Reader; mIRC; Mozilla Firefox; Netscape; Microsoft Outlook Express; Microsoft Outlook | ||||
| Type: | Input Validation | ||||
| Description: | There is a vulnerability in Microsoft Windows that could be exploited by remote attackers to compromise a vulnerable system. The issue exists in the interaction between ShellExecute and IE7 URLMon component when handling malformed URLs. Successful exploitation would allow the attacker to execute arbitrary command on the vulnerable client system within the context of the logged in user. | ||||
| Situation |
HTTP_Mozilla-Firefox-Multiple-URI-Handlers-Command-Execution
|
||||
| References: |
|
MS07-060 Microsoft-Word-Malformed-String-Memory-Corruption
| About this vulnerability: | A buffer overflow vulnerability in Microsoft Word | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-125-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows; Mac OS X | ||||
| Software: | Microsoft Word; Microsoft Office | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a buffer overflow vulnerability in Microsoft Word processes. The vulnerability is a result of insufficient boundary checking while parsing a font table structure in a specially crafted file. A remote attacker can exploit this vulnerability by enticing the target user to open a crafted Word document, potentially causing arbitrary code to be injected and executed in the security context of the current user. | ||||
| Situation |
HTTP_Microsoft-Word-For-Macintosh-Version-5-Document
|
||||
| References: |
|
MS07-059 Microsoft-Windows-Sharepoint-Services-Cross-Site-Scripting
| About this vulnerability: | A cross-site scripting vulnerability in Microsoft Office SharePoint Server | ||||
| Risk: | Low | ||||
| First detected in: | sgpkg-ips-125-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Microsoft Office SharePoint Server | ||||
| Type: | Cross-site Scripting | ||||
| Description: | There is a cross-site scripting vulnerability in Microsoft Office SharePoint Server. The flaw is due to a lack of input validation when processing the URL request from the client. The flaw may be exploited by malicious users to execute arbitrary HTML code on target user's web browser in the context of a trusted web site. | ||||
| Situation |
HTTP_CRL-Microsoft-Windows-Sharepoint-Services-Cross-Site-Scripting
|
||||
| References: |
|
MS07-058 MSRPC-NTLMSSP-Authentication-Null-Session-Denial-Of-Service
| About this vulnerability: | Denial of service vulnerability in MSRPC NTLMSSP authentication | ||||
| Risk: | Low | ||||
| First detected in: | sgpkg-ips-125-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | <os> | ||||
| Type: | Malfunction | ||||
| Description: | Microsoft MSRPC service has an integer overflow vulnerability that can be triggered via the NTLMSSP authentication method. A specially crafted MSRPC connection where a NULL session is first established with NTLMSSP authentication and later used with a crafted authentication level may result in crashing a vulnerable Windows host. The vulnerability can be exploited by unauthenticated remote attackers. | ||||
| Situation |
MSRPC-TCP_NTLMSSP-Authentication-Null-Session-Denial-Of-Service
|
||||
| References: |
|
MS07-055 Microsoft-Windows-Kodak-Image-Viewer-Code-Execution
| About this vulnerability: | A buffer overflow vulnerability in Microsoft Windows | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-129-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows 2000 SP4; Windows XP SP2; Windows 2003 SP1; Windows 2003 SP2 | ||||
| Software: | <os> | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a buffer overflow vulnerability in Microsoft Windows Kodak Image Viewer. The vulnerability is due to improper parsing of specially crafted TIFF image files. An attacker can exploit the vulnerability by constructing a specially crafted image and enticing a victim to open the malicious image with an affected version of product. Successful exploitation of this vulnerability would result in arbitrary code execution in the context of the logged-in user. | ||||
| Situation |
HTTP_SS-Microsoft-Windows-Kodak-Image-Viewer-Code-Execution
|
||||
| Situation |
E-Mail_BS-Microsoft-Windows-Kodak-Image-Viewer-Code-Execution
|
||||
| References: |
|
MS07-052 Business-Objects-Crystal-Reports-Rpt-File-Handling
| About this vulnerability: | A buffer overflow vulnerability in Business Objects Crystal Reports | ||||
| Risk: | Moderate | ||||
| First detected in: | sgpkg-ips-124-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Business Objects Crystal Enterprise; Crystal Reports; Microsoft Visual Studio 2005; Microsoft Visual Studio .NET 2002; Microsoft Visual Studio .NET 2003 | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a buffer overflow vulnerability in the way Business Objects Crystal Reports handles RPT files. Versions of Crystal Reports are included with Microsoft's Visual Studio .NET 2002 and 2003, as well as Visual Studio 2005 products. The vulnerable application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer. An attacker may exploit this issue by enticing a user into opening a malicious RPT file, resulting in the execution of arbitrary code with the privileges of the currently logged-in user. Failed exploit attempts are likely to result in denial of service conditions. | ||||
| Situation |
HTTP_Business-Objects-Crystal-Reports-Rpt-File-Handling
|
||||
| References: |
|
MS07-051 HTTP_Microsoft-Agent-Crafted-Url-Stack-Buffer-Overflow
| About this vulnerability: | Buffer overflow vulnerability in Microsoft Agent | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-121-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows 2000 | ||||
| Software: | Microsoft Agent | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a buffer overflow vulnerability in the Microsoft Windows Agent application. The flaw is due to wrongly copying an overly large string to a fixed-size stack buffer within the code of the agentdpv.dll Dynamic Link Library. By persuading the target user to open a malicious web page, an attacker may execute arbitrary code on the target system within the privileges of the currently logged-on user. | ||||
| Situation |
HTTP_SS-Microsoft-Agent-Crafted-Url-Stack-Buffer-Overflow
|
||||
| References: |
|
MS07-045 HTTP-Microsoft-Ie-ActiveX-Object-IObjectsafety-Implementation-Code-Execution
| About this vulnerability: | Code execution vulnerability in the tblinf32.dll ActiveX control in Microsoft Internet Explorer | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-118-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Internet Explorer | ||||
| Type: | Malfunction | ||||
| Description: | There is a code execution vulnerability in the tblinf32.dll ActiveX control in Microsoft Internet Explorer. A remote attacker can exploit this vulnerability by enticing a user to visit a crafted web site, which allows the attacker to execute arbitrary code with the privileges of the currently logged in user. | ||||
| Situation |
HTTP_SS-Microsoft-Ie-ActiveX-Object-IObjectsafety-Implementation-Code-Execution
|
||||
| References: |
|
MS07-045 HTTP_SS-Microsoft-Internet-Explorer-CSS-Strings-Parsing-Memory-Corruption
| About this vulnerability: | A vulnerability in Microsoft Internet Explorer | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-142-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Internet Explorer | ||||
| Type: | Malfunction | ||||
| Description: | There is a remote code execution vulnerability in Microsoft Internet Explorer. The flaw is caused by improper handling of malformed Cascading Style Sheet (CSS) content. A remote attacker can exploit this vulnerability by enticing the target user to open a crafted web page, potentially causing arbitrary code to be injected and executed in the security context of the current user. | ||||
| Situation |
HTTP_SS-Microsoft-Internet-Explorer-CSS-Strings-Parsing-Memory-Corruption
|
||||
| References: |
|
MS07-045 Microsoft-Visual-Studio-PDWizard.ocx-ActiveX-Control-Memory-Corruption
| About this vulnerability: | A vulnerability in Microsoft Visual Basic and Visual Studio | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-142-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Microsoft Visual Basic; Microsoft Visual Studio | ||||
| Type: | Malfunction | ||||
| Description: | There is a remote code execution vulnerability in Microsoft's ActiveX control pdwizard.ocx, distributed with Microsoft Visual Studio and Microsoft Visual Basic. The vulnerability is due to memory corruption that occurs when the affected control is instantiated in Internet Explorer. A remote attacker can exploit this vulnerability by enticing the target user to open a crafted web page, potentially causing arbitrary code to be injected and executed in the security context of the currently logged on user. | ||||
| Situation |
HTTP_SS-Microsoft-Visual-Studio-PDWizard.ocx-ActiveX-Control-Memory-Corruption
|
||||
| References: |
|
MS07-043 HTTP-Microsoft-OLE-Automation-String-Manipulation-Heap-Overflow
| About this vulnerability: | Buffer overflow vulnerability in the Microsoft Object Linking and Embedding Automation library | ||||
| Risk: | Moderate | ||||
| First detected in: | sgpkg-ips-121-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | <os> | ||||
| Type: | Integer Overflow | ||||
| Description: | There is a buffer overflow vulnerability in the Microsoft Object Linking and Embedding Automation library. The vulnerability is due to a lack of parameter checking in the substringData method. By enticing a user to visit a crafted web site, a remote attacker can execute non-privileged arbitrary code. | ||||
| Situation |
HTTP_Core-Services-And-OLE-Automation-SubstringData-Memory-Corruption
|
||||
| References: |
|
MS07-042 HTTP-Microsoft-Xml-Core-Services-Memory-Corruption-Vulnerability
| About this vulnerability: | A vulnerability in Microsoft XML Core Services | ||||
| Risk: | Moderate | ||||
| First detected in: | sgpkg-ips-117-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | <os> | ||||
| Type: | Integer Overflow | ||||
| Description: | There exists an integer overflow vulnerability in Microsoft XML Core Services. The vulnerability is caused due to lack of parameter check in the substringData method of various MSXML ActiveX controls. A remote attack can exploit these vulnerability by enticing the target user to open a crafted web page, potentially causing arbitrary code to be injected and executed in the security context of the current user. | ||||
| Situation |
HTTP_Core-Services-And-OLE-Automation-SubstringData-Memory-Corruption
|
||||
| References: |
|
MS07-041 HTTP-IIS-Malformed-Url-Denial-Of-Service
| About this vulnerability: | IIS malformed URL DoS | ||||
| Risk: | Moderate | ||||
| First detected in: | sgpkg-ips-63-1210 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | IIS | ||||
| Type: | Malfunction | ||||
| Description: | Microsoft IIS suffers from a vulnerability in the handling of malformed URLs. If a dynamically linked library (DLL) resource is requested multiple times via a crafted request, the server may shut down. A remote attacker can trigger the vulnerability by sending a request with the following format: GET /test/test.dll/%01/~0, where the last character may be any digit, and the previous directory name must contain a character from a certain range. A successful exploit shuts down the server, resulting in a denial of service situation. | ||||
| Situation |
HTTP_IIS-Malformed-Url-Denial-Of-Service
|
||||
| References: |
|
MS07-040 Microsoft-ASP.NET-Null-Byte-Termination-Vulnerability
| About this vulnerability: | Vulnerability in Microsoft .NET Framework | ||||
| Risk: | Low | ||||
| First detected in: | sgpkg-ips-156-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Microsoft .NET Framework | ||||
| Type: | Malfunction | ||||
| Description: | There is a a vulnerability in Microsoft .NET Framework was detected. ASP.NET component of .NET Framework may allow access to configuration files and other sensitive information when the URI is terminated with an extra null character. | ||||
| Situation |
HTTP_CSU-Microsoft-ASP.NET-Null-Byte-Termination-Vulnerability
|
||||
| References: |
|
MS07-036 Microsoft-Excel-rtWindow1-Record-Handling-Code-Execution
| About this vulnerability: | A memory corruption vulnerability in Microsoft Excel | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-114-2032 | ||||
| Last changed: | sgpkg-ips-292-4219 | ||||
| Platform: | Generic | ||||
| Software: | Microsoft Excel; Microsoft Excel Viewer | ||||
| Type: | Input Validation | ||||
| Description: | There is a memory corruption vulnerability in Microsoft Excel. The memory corrution happens when Excel attempts to open files that contain invalid values within the rtWindow1 records. A remote attacker can exploit this vulnerability by persuading a target user to open a specially crafted XLS file, potentially causing arbitrary code to be injected and executed in the security context of the logged in user. | ||||
| Situation |
HTTP_Microsoft-Excel-rtWindow1-Record-Handling-Code-Execution
|
||||
| References: |
|
MS07-036 Microsoft-Excel-Version-Information-Handling-Code-Execution
| About this vulnerability: | Memory corruption vulnerability in Microsoft Excel | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-114-2032 | ||||
| Last changed: | sgpkg-ips-292-4219 | ||||
| Platform: | Generic | ||||
| Software: | Microsoft Excel; Microsoft Excel Viewer | ||||
| Type: | Input Validation | ||||
| Description: | There is a memory corruption vulnerability in Microsoft Excel. The vulnerability is a result of insufficient data validation while processing the Version Number field in a BOF record. A remote attacker can exploit this vulnerability by enticing the target user to open a crafted Excel file, potentially causing arbitrary code to be injected and executed in the security context of the current user. | ||||
| Situation |
HTTP_Microsoft-Excel-Version-Information-Handling-Code-Execution
|
||||
| References: |
|
MS07-036 Microsoft-Excel-Workbook-Workspace-Designation-Handling-Code-Execution
| About this vulnerability: | A memory corruption vulnerability in Microsoft Excel | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-114-2032 | ||||
| Last changed: | sgpkg-ips-292-4219 | ||||
| Platform: | Generic | ||||
| Software: | Microsoft Excel; Microsoft Excel Viewer | ||||
| Type: | Input Validation | ||||
| Description: | There is a memory corruption vulnerability in Microsoft Excel. The vulnerability is a result of insufficient data validation while processing the SubStreamType field in a BOF record. A remote attacker can exploit this vulnerability by enticing the target user to open a crafted Excel file, potentially causing arbitrary code to be injected and executed in the security context of the current user. | ||||
| Situation |
HTTP_Microsoft-Excel-Workbook-Workspace-Designation-Handling-Code-Execution
|
||||
| References: |
|
MS07-035 Microsoft-Windows-Resource-URI-Win32-API-Code-Execution-Vulnerability
| About this vulnerability: | A code execution vulnerability in Microsoft Windows' resource URI protocol handler | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-113-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows 2000; Windows XP; Windows 2003 | ||||
| Software: | <os> | ||||
| Type: | Input Validation | ||||
| Description: | There is a vulnerability in the resource protocol handler in Microsoft Windows. The vulnerability is caused by the lack of proper validation of API parameters. An attacker can exploit the vulnerability for code execution by manipulating an application into making API calls with malformed parameters. Any code injected into the application would be executed within the security context of the currently logged in user. | ||||
| Situation |
HTTP_Microsoft-Windows-Resource-URI-Win32-API-Code-Execution-Vulnerability
|
||||
| References: |
|
MS07-033 HTTP-Internet-Explorer-Urlmon.dll-Com-Object-Instantiation-Memory-Corruption
| About this vulnerability: | Memory corruption vulnerability in the instantiation of certain COM objects in Microsoft Internet Explorer | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-111-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Internet Explorer | ||||
| Type: | Malfunction | ||||
| Description: | There is a memory corruption vulnerability in the instantiation of certain COM objects in Microsoft Internet Explorer. The vulnerability can be exploited remotely by persuading a user to visit a malicious web site with the vulnerable browser to execute arbitrary code under the context of the currently logged-in user. | ||||
| Situation |
HTTP_SS-Internet-Explorer-Urlmon.dll-Com-Object-Instantiation-Memory-Corruption
|
||||
| References: |
|
MS07-033 HTTP-Microsoft-Internet-Explorer-CSS-Tag-Handling-Memory-Corruption
| About this vulnerability: | Memory corruption vulnerability in the handling of certain HTML tags containing a specially crafted CSS style attribute in Microsoft Internet Explorer | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-111-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Internet Explorer 6.0 | ||||
| Type: | Malfunction | ||||
| Description: | There is a memory corruption vulnerability in the handling of certain HTML tags containing a specially crafted CSS style attribute in Microsoft Internet Explorer. The vulnerability can be exploited remotely by persuading a user to visit a malicious web site with the vulnerable browser to execute arbitrary code under the context of the currently logged-in user. | ||||
| Situation |
HTTP_SS-Microsoft-Internet-Explorer-CSS-Tag-Handling-Memory-Corruption
|
||||
| References: |
|
MS07-033 Internet-Explorer-7-Navigation-Canceled-Page-Cross-Site-Scripting
| About this vulnerability: | A cross-site scripting vulnerability in Microsoft Internet Explorer | ||||
| Risk: | Moderate | ||||
| First detected in: | sgpkg-ips-101-1314 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Internet Explorer | ||||
| Type: | Cross-site Scripting | ||||
| Description: | There is a cross-site scripting vulnerability in Microsoft Internet Explorer 7. The vulnerability is due to an input validation error in the local resource page navcancl.htm when generating the page refresh link in Internet Explorer 7. Successful exploitation can allow the attacker to execute a cross-site scripting or phishing attack. | ||||
| Situation |
HTTP_Internet-Explorer-7-Navigation-Canceled-Page-Cross-Site-Scripting
|
||||
| References: |
|
MS07-033 Microsoft-Internet-Explorer-Speech-Control-Memory-Corruption
| About this vulnerability: | Remote exploitable vulnerability in Microsoft Speech API | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-111-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Internet Explorer 5.0; Internet Explorer 6.0; Internet Explorer 7.0 | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a buffer overflow vulnerability in the Microsoft Speech API (SAPI) ActiveX controls. The vulnerability can be triggered by passing overly long string to various method of the SAPI ActiveX controls. An attacker can exploit this vulnerability for code execution by enticing a target user to open a malicious HTML document. Any code injected using this vulnerability would be executed in the security context of the currently logged in user. | ||||
| Situation |
HTTP_SS-Microsoft-Internet-Explorer-Speech-Control-Memory-Corruption
|
||||
| References: |
|
MS07-031 HTTPS-Microsoft-Schannel-Security-Package-Compromise
| About this vulnerability: | Remote code execution vulnerability in Microsoft Schannel Security Package | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-111-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows 2000;Windows XP;Windows 2003 | ||||
| Software: | <os> | ||||
| Type: | Buffer Overflow | ||||
| Description: | Microsoft Schannel SSL client does not handle invalid SSL ServerKeyExchange messages correctly. A malicious SSL server can use a specially crafted handshake message to execute arbitrary code on vulnerable SSL clients connecting to it. | ||||
| Situation |
HTTPS_SS-Microsoft-Schannel-Security-Package-Compromise
|
||||
| References: |
|
MS07-030 Microsoft-Visio-Version-Number-Handling-Code-Execution
| About this vulnerability: | A vulnerability in Microsoft Visio | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-114-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Microsoft Visio | ||||
| Type: | Input Validation | ||||
| Description: | There is a remote code-execution vulnerability in Microsoft Visio. The vulnerability is due to insufficient validating of user-supplied data while processing Version Number. A remote attacker can exploit this vulnerability by enticing the target user to open a crafted Microsoft Visio file, potentially causing arbitrary code to be injected and executed in the security context of the current user. | ||||
| Situation |
HTTP_Microsoft-Visio-Version-Number-Handling-Code-Execution
|
||||
| References: |
|
MS07-029 Microsoft-Windows-DNS-Server-RPC-Management-Interface-Buffer-Overflow
| About this vulnerability: | Buffer overflow vulnerability in Microsoft Windows Domain Name System Server services | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-103-1314 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows 2000 Server; Windows 2000 Advanced Server; Windows 2000 Datacenter Server; Windows 2003 | ||||
| Software: | <os> | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a stack-based buffer overflow vulnerability in Microsoft Windows Domain Name System Server services. A crafed RPC call with a malicious string as the zone name parameter allows arbitrary code execution with the privileges of the affected service process. | ||||
| Situation |
Generic_Microsoft-Windows-DNS-Server-RPC-Management-Interface-Buffer-Overflow
|
||||
| Situation |
MSRPC-TCP_CPS-Microsoft-Windows-DNS-Server-RPC-Management-Interface-BOF
|
||||
| References: |
|
MS07-028 Microsoft-CAPICOM-Certificates-ActiveX-Control-Vulnerability
| About this vulnerability: | Vulnerable ActiveX control allow access to the local system | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-113-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Microsoft BizTalk Server; Microsoft CAPICOM | ||||
| Type: | Malfunction | ||||
| Description: | There is a vulnerability in the Microsoft Cryptographic API Component Object Model (CAPICOM) Certificates ActiveX control included in Microsoft BizTalk Server. The vulnerability allows arbitrary code execution in the context of the current user. | ||||
| Situation |
HTTP_Microsoft-CAPICOM-Certificates-ActiveX-Control-Vulnerability
|
||||
| References: |
|
MS07-027 Internet-Explorer-Chtskdic.dll-Com-Object-Instantiation-Memory-Corruption
| About this vulnerability: | Memory corruption vulnerability in Microsoft Internet Explorer | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-107-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Internet Explorer | ||||
| Type: | Malfunction | ||||
| Description: | There is a memory corruption vulnerability in Microsoft Internet Explorer. The flaw is due to improper handling of a COM object implemented by chtskdic.dll that is not designed to work with Internet Explorer. By persuading a user to visit a malicious web site, a remote attacker may execute arbitrary code on the target system with the privileges of the currently logged on user. | ||||
| Situation |
HTTP_Internet-Explorer-MSOE-CHTSKDIC-And-IMSKDIC-Com-Object-Vulnerability
|
||||
| References: |
|
MS07-026 IMAP-Microsoft-Exchange-Server-Literal-Processing-Buffer-Overflow
| About this vulnerability: | Buffer overflow in Microsoft Exchange Server when processing IMAP literal octets | ||||
| Risk: | Moderate | ||||
| First detected in: | sgpkg-ips-106-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Exchange Server 2000 | ||||
| Type: | Buffer Overflow | ||||
| Description: | Certain versions of Microsoft Exchange Server 2000 have a buffer overflow vulnerability in the handling of the IMAP protocol. IMAP protocol messages using the IMAP command continuation method specifying a large number of octets may cause a buffer overflow and memory corruption in the server process. The vulnerability allows remote attackers to perform denial of service attacks on vulnerable Exchange servers. | ||||
| Situation |
IMAP_Microsoft-Exchange-Server-Literal-Processing-Buffer-Overflow
|
||||
| References: |
|
MS07-026 Microsoft-Exchange-Server-ICalendar-DOS
| About this vulnerability: | Null Pointer dereference in Exchange Server allows Denial of Service | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-107-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Exchange Server | ||||
| Type: | Malfunction | ||||
| Description: | There is a denial of service vulnerability in Microsoft Exchange Server, due to the way Microsoft Exchange Server handles calendar content requests, known asiCal. The vulnerability is a result of NULL pointer dereference when processing crafted iCalendar objects inside email messages. Successful exploitation of this vulnerability can allow a remote unauthenticated attacker to terminate the Microsoft Exchange Information Store service. | ||||
| Situation |
SMTP_Microsoft-Exchange-Server-iCal-Denial-Of-Service
|
||||
| References: |
|
MS07-026 Microsoft-Exchange-Server-Mime-Base64-Decoding-Code-Execution
| About this vulnerability: | Buffer overflow vulnerability in Microsoft Exchange Server | ||||
| Risk: | Critical | ||||
| First detected in: | sgpkg-ips-107-2032 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Exchange Server | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a buffer overflow vulnerability in Microsoft Exchange Server. A remote unauthenticated attacker can exploit this vulnerability by sending an email message with malformed Base64 encoded MIME content to cause a denial of service or compromise the vulnerable system. | ||||
| Situation |
SMTP_Microsoft-Exchange-Server-Mime-Base64-Decoding-Code-Execution
|
||||
| References: |
|
MS07-023 Microsoft-Excel-Biff-File-Format-Named-Graph-Record-Parsing-Stack-Overflow
| About this vulnerability: | A stack overflow vulnerability in Microsoft Excel | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-106-2032 | ||||
| Last changed: | sgpkg-ips-292-4219 | ||||
| Platform: | Generic | ||||
| Software: | Microsoft Excel; Microsoft Excel Viewer | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a buffer overflow vulnerability in Microsoft Excel and Microsoft Excel Viewer. The vulnerability is the result of insufficient boundary checking when parsing a Named Graph Record from native OLE formatted files. A remote attacker can exploit this vulnerability by enticing the target user to open a crafted Excel file, potentially causing arbitrary code to be injected and executed in the security context of the current user. | ||||
| Situation |
HTTP_Microsoft-Excel-Named-Graph-Record-Parsing-Stack-Overflow
|
||||
| References: |
|
MS07-019 Microsoft-Windows-UPnP-Service-Remote-Code-Execution
| About this vulnerability: | Buffer overflow vulnerability in Microsoft Windows Unversal Plug and Play service | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-102-1314 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows XP SP2; Windows XP 64-bit SP0; Windows XP 64-bit SP2 | ||||
| Software: | <os> | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a memory corruption vulnerability in the Microsoft Windows Universal Plug and Play service. The vulnerability is due to a failure to handle specially crafted HTTP requests. A remote attacker can exploit this vulnerability to cause a denial of service condition, or inject and execute arbitrary code on the target system with the privileges of the Local Service account. | ||||
| Situation |
Generic_Microsoft-Windows-UPnP-Service-Remote-Code-Execution
|
||||
| References: |
|
MS07-017 Ani-Windows-Animated-Cursor-Code-Execution
| About this vulnerability: | Incorrect length field buffer overflow | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-101-1314 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows 2000 SP4; Windows 2003; Windows XP SP2; Windows Vista | ||||
| Software: | <os> | ||||
| Type: | Buffer Overflow | ||||
| Description: | Microsoft Windows incorrectly parses the AnimationHeader information in ANI files. The length of the header should be 36 bytes, but the value is not checked properly. This allows specially-crafted ANI files to cause a buffer overflow, leading to arbitrary code execution. Animated cursors can be supplied by web pages, which allows malicious web sites to compromise systems when they are viewed with Internet Explorer. Also, viewing folders that contain malicious ANI files causes a buffer overflow in Windows Explorer. | ||||
| Situation |
HTTP_Ani-Windows-Animationheader-Length-Buffer-Overflow
|
||||
| Situation |
E-Mail_BS-Ani-Windows-Animationheader-Length-Buffer-Overflow
|
||||
| References: |
|
MS07-016 FTP-Microsoft-Internet-Explorer-FTP-Response-Parsing-Memory-Corruption
| About this vulnerability: | Memory corruption vulnerability in Internet Explorer | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-97-1314 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Internet Explorer | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a memory corruption vulnerability in Internet Explorer. By persuading a target user to visit a malicious web page, a remote attacker may execute arbitrary code on the target host with the privileges of the currently logged in user. | ||||
| Situation |
FTP_Microsoft-Internet-Explorer-FTP-Response-Parsing-Memory-Corruption
|
||||
| References: |
|
MS07-016 HTTP_Internet-Explorer-Imjpcksid.dll-Com-Object-Memory-Corruption
| About this vulnerability: | Memory corruption vulnerability in Microsoft Internet Explorer | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-97-1314 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Internet Explorer | ||||
| Type: | Malfunction | ||||
| Description: | There is a memory corruption vulnerability in Microsoft Internet Explorer. The flaw is due to improper handling of certain COM objects that are not designed to work with Internet Explorer. By persuading a user to visit a malicious web site, a remote attacker may execute arbitrary code on the target system with the privileges of the currently logged in user. | ||||
| Situation |
HTTP_Internet-Explorer-Imjpcksid.dll-Com-Object-Memory-Corruption
|
||||
| References: |
|
MS07-016 HTTP_Internet-Explorer-Multiple-Com-Objects-Instantiation-Memory-Corruption
| About this vulnerability: | Memory corruption vulnerability in Microsoft Internet Explorer | ||||||
| Risk: | Moderate | ||||||
| First detected in: | sgpkg-ips-97-1314 | ||||||
| Last changed: | sgpkg-ips-273-4219 | ||||||
| Platform: | Windows | ||||||
| Software: | Internet Explorer | ||||||
| Type: | Malfunction | ||||||
| Description: | There is a vulnerability in the way Microsoft Internet Explorer instantiates certain COM objects that are not designed to be used as ActiveX controls. When instantiation of such COM objects is attempted by Internet Explorer, the application memory can be corrupted as a result. Successful exploitation of this vulnerability can allow for arbitrary code execution within the security context of the currently logged in user. | ||||||
| Situation |
HTTP_SS-Internet-Explorer-Multiple-Com-Objects-Instantiation-Memory-Corruption
|
||||||
| References: |
|
MS07-015 Microsoft-Office-Drawing-Record-Msofbtopt-Code-Execution
| About this vulnerability: | Code execution vulnerability in Microsoft Office | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-102-1314 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Generic | ||||
| Software: | Microsoft Office; Microsoft Project; Microsoft Visio | ||||
| Type: | Input Validation | ||||
| Description: | There is a vulnerability in Microsoft Office products. The flaw is due to improper handling of Microsoft Office files containing malformed records. An attacker can exploit this vulnerability by enticing an unsuspecting user to open a malicious Office document. This flaw may allow the attacker to execute arbitrary code in the context of the currently logged-in user. | ||||
| Situation |
HTTP_Microsoft-Office-Drawing-Record-Msofbtopt-Code-Execution
|
||||
| References: |
|
MS07-014 HTTP-Microsoft-Word-Formatted-Disk-Pages-Table-Memory-Corruption
| About this vulnerability: | Memory corruption vulnerability in Microsoft Word | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-88-1314 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Generic | ||||
| Software: | Microsoft Word | ||||
| Type: | Malfunction | ||||
| Description: | There is a memory corruption vulnerability in Microsoft Word. The vulnerability can be exploited by delivering a malicious Word document to the target user who opens it with the affected application. This leads to a DoS terminating the vulnerable appalication or arbitrary code execution with the privileges of the currently logged in user. | ||||
| Situation |
HTTP_Microsoft-Word-Formatted-Disk-Pages-Table-Memory-Corruption
|
||||
| References: |
|
MS07-014 HTTP-Microsoft-Word-Section-Table-Array-Buffer-Overflow
| About this vulnerability: | Buffer overflow vulnerability in Microsoft Word | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-97-1314 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Microsoft Word | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a stack buffer overflow vulnerability in Microsoft Word. The vulnerability can be exploited by delivering a malicious Word document with a malformed PLCFSED record inside the Table Stream to the target user who opens it with the affected application. This leads to a denial of service condition terminating the vulnerable appalication or arbitrary code execution with the privileges of the currently logged in user. | ||||
| Situation |
HTTP_Microsoft-Word-Section-Table-Array-Buffer-Overflow
|
||||
| Situation |
E-Mail_BS-Microsoft-Word-Section-Table-Array-Buffer-Overflow
|
||||
| References: |
|
MS07-009 HTTP-Microsoft-Internet-Explorer-Adodb.Connection-Execute-Memory-Corruption
| About this vulnerability: | Memory corruption vulnerability in Internet Explorer | ||||
| Risk: | Moderate | ||||
| First detected in: | sgpkg-ips-83-1314 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Internet Explorer | ||||
| Type: | Malfunction | ||||
| Description: | There is a memory corruption vulnerability in Internet Explorer. The vulnerability can be exploited by persuading a target user to view a malicious HTML page with a vulnerable browser. This causes a DoS or arbitrary non-privileged code execution on the victim's computer. | ||||
| Situation |
HTTP_SS-Vulnerable-Microsoft-Internet-Explorer-Function-Called
|
||||
| References: |
|
MS07-008 HTTP-Microsoft-HTML-Help-ActiveX-Control-Remote-Code-Execution-Vulnerability
| About this vulnerability: | Vulnerability in HTML Help ActiveX Control Can Allow Remote Code Execution | ||||
| Risk: | Moderate | ||||
| First detected in: | sgpkg-ips-96-1314 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows 2000; Windows 2003; Windows XP | ||||
| Software: | <os> | ||||
| Type: | Malfunction | ||||
| Description: | There is a vulnerability in the Microsoft Windows HTML Help ActiveX control. The flaw is caused by an improper check during the processing of the parameters in HTML Help Control ActiveX Objects. An attacker can exploit this vulnerability to inject and execute arbitrary code in the security context of the currently logged in user. | ||||
| Situation |
HTTP_Vulnerable-HTML-Help-ActiveX-Control-Access
|
||||
| References: |
|
MS07-005 Microsoft-Step-By-Step-Interactive-Training-Bookmark-Link-File-BOF
| About this vulnerability: | Buffer overflow vulnerability in Microsoft Step-by-Step Interactive Training | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-97-1314 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Microsoft Step-by-Step Interactive Training | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a stack-based buffer overflow vulnerability in Microsoft Step-by-Step Interactive Training. By delivering a malicious bookmark link file to a target user who opens the file with a vulnerable version of the affected product, a remote attacker may cause a denial of service terminating the affected application or execute arbitrary code with the privileges of the currently logged in user. | ||||
| Situation |
HTTP_Malicious-Microsoft-Step-By-Step-Interactive-Training-Bookmark-Link-File
|
||||
| References: |
|
MS07-004 Microsoft-Internet-Explorer-VML-Buffer-Overrun
| About this vulnerability: | A format string vulnerability in Apple iPhoto | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-91-1314 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows 2000 SP4; Windows XP; Windows XP 64-bit; Windows 2003; Windows 2003 64-bit | ||||
| Software: | Internet Explorer 5.0; Internet Explorer 6.0; Internet Explorer 7.0 | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a buffer overrun vulnerability in Microsoft Internet Explorer. A crafted Vector Markup Language (VML) formatted file may be used to execute code in the privilege of the current user. | ||||
| Situation |
HTTP_Microsoft-Internet-Explorer-VML-Buffer-Overrun
|
||||
| References: |
|
MS07-003 Microsoft-Outlook-iCal-Meeting-Request-Vevent-Record-Memory-Corruption
| About this vulnerability: | A memory corruption vulnerability in Microsoft Outlook | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-92-1314 | ||||
| Last changed: | sgpkg-ips-273-4219 | ||||
| Platform: | Windows | ||||
| Software: | Microsoft Outlook | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a memory corruption vulnerability in Microsoft Outlook. A crafted iCal meeting request may be used to execute arbitary code in the context of the current user. | ||||
| Situation |
E-Mail_BS-Microsoft-Outlook-iCal-Meeting-Request-Vevent-Record-Memory-Corruption
|
||||
| References: |
|
MS07-002 Microsoft-Excel-Column-Record-Handling-Memory-Corruption
| About this vulnerability: | A memory corruption vulnerability in Microsoft Excel | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-93-1314 | ||||
| Last changed: | sgpkg-ips-292-4219 | ||||
| Platform: | Windows; Mac OS | ||||
| Software: | Microsoft Excel | ||||
| Type: | Malfunction | ||||
| Description: | There is a memory corruption vulnerability in Microsoft Excel. A crafted Excel spreadsheet file (XLS) can be used to terminate the affected product or execute non-privileged arbitary code. | ||||
| Situation |
HTTP_Microsoft-Excel-Column-Record-Handling-Memory-Corruption
|
||||
| References: |
|
MS07-002 Microsoft-Excel-Malformed-Imdata-Record
| About this vulnerability: | A memory corruption vulnerability in Microsoft Excel | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-91-1314 | ||||
| Last changed: | sgpkg-ips-292-4219 | ||||
| Platform: | Windows; Mac OS X | ||||
| Software: | Microsoft Excel | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a buffer overflow vulnerability in Microsoft Excel. A crafted Excel spreadsheet file (XLS) may be used to execute code in the privilege of the current user. | ||||
| Situation |
HTTP_Microsoft-Excel-Malformed-Imdata-Record
|
||||
| References: |
|
MS07-002 Microsoft-Excel-Malformed-Palette-Record-Memory-Corruption
| About this vulnerability: | A memory corruption vulnerability in Microsoft Excel | ||||
| Risk: | High | ||||
| First detected in: | sgpkg-ips-91-1314 | ||||
| Last changed: | sgpkg-ips-292-4219 | ||||
| Platform: | Windows; Mac OS | ||||
| Software: | Microsoft Excel; Microsoft Excel Viewer | ||||
| Type: | Buffer Overflow | ||||
| Description: | There is a buffer overflow vulnerability in Microsoft Excel. A crafted Excel spreadsheet file (XLS) may be used to execute code in the privilege of the current user. | ||||
| Situation |
HTTP_Microsoft-Excel-Malformed-Palette-Record-Memory-Corruption
|
||||
| References: |
|
