Lucene search

K
cve[email protected]CVE-2006-0031
HistoryMar 14, 2006 - 11:02 p.m.

CVE-2006-0031

2006-03-1423:02:00
CWE-119
web.nvd.nist.gov
35
cve-2006-0031
stack-based buffer overflow
microsoft excel
microsoft office
arbitrary code execution
nvd

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.43 Medium

EPSS

Percentile

97.4%

Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.

Affected configurations

NVD
Node
microsoftofficeMatch2000sp3
OR
microsoftofficeMatch2003sp1
OR
microsoftofficeMatch2003sp2
OR
microsoftofficeMatch2004mac
OR
microsoftofficeMatchv.xmac
OR
microsoftofficeMatchxpsp3

References

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.43 Medium

EPSS

Percentile

97.4%