Lucene search

K
cveMitreCVE-2004-0848
HistoryFeb 08, 2005 - 5:00 a.m.

CVE-2004-0848

2005-02-0805:00:00
mitre
web.nvd.nist.gov
50
cve-2004-0848
buffer overflow
microsoft office xp
remote code execution
url file location
security vulnerability

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

Low

EPSS

0.482

Percentile

97.5%

Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) “%0a” (carriage return) in .rtf filenames.

Affected configurations

Nvd
Node
microsoftoffice
OR
microsoftofficeMatchxpsp1
OR
microsoftofficeMatchxpsp2
OR
microsoftofficeMatchxpsp3
OR
microsoftpowerpointMatch2002
OR
microsoftpowerpointMatch2002sp1
OR
microsoftpowerpointMatch2002sp2
OR
microsoftpowerpointMatch2002sp3
OR
microsoftprojectMatch2002
OR
microsoftprojectMatch2002sp1
OR
microsoftvisioMatch2002
OR
microsoftvisioMatch2002sp1
OR
microsoftvisioMatch2002sp2
OR
microsoftvisioMatch2002sp2professional
OR
microsoftvisioMatch2002sp2standard
OR
microsoftwordMatch2002
OR
microsoftwordMatch2002sp1
OR
microsoftwordMatch2002sp2
OR
microsoftwordMatch2002sp3
OR
microsoftworksMatch2002
OR
microsoftworksMatch2003
OR
microsoftworksMatch2004
VendorProductVersionCPE
microsoftoffice*cpe:2.3:a:microsoft:office:*:*:*:*:*:*:*:*
microsoftofficexpcpe:2.3:a:microsoft:office:xp:sp1:*:*:*:*:*:*
microsoftofficexpcpe:2.3:a:microsoft:office:xp:sp2:*:*:*:*:*:*
microsoftofficexpcpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*
microsoftpowerpoint2002cpe:2.3:a:microsoft:powerpoint:2002:*:*:*:*:*:*:*
microsoftpowerpoint2002cpe:2.3:a:microsoft:powerpoint:2002:sp1:*:*:*:*:*:*
microsoftpowerpoint2002cpe:2.3:a:microsoft:powerpoint:2002:sp2:*:*:*:*:*:*
microsoftpowerpoint2002cpe:2.3:a:microsoft:powerpoint:2002:sp3:*:*:*:*:*:*
microsoftproject2002cpe:2.3:a:microsoft:project:2002:*:*:*:*:*:*:*
microsoftproject2002cpe:2.3:a:microsoft:project:2002:sp1:*:*:*:*:*:*
Rows per page:
1-10 of 221

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

Low

EPSS

0.482

Percentile

97.5%