Lucene search

K
cve[email protected]CVE-2008-0108
HistoryFeb 12, 2008 - 11:00 p.m.

CVE-2008-0108

2008-02-1223:00:00
CWE-119
web.nvd.nist.gov
32
cve-2008-0108
buffer overflow
wkcvqd01.dll
microsoft works
office 2003
works 8.0
works suite 2005
remote code execution
vulnerability

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.951 High

EPSS

Percentile

99.3%

Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka “Microsoft Works File Converter Field Length Vulnerability.”

Affected configurations

NVD
Node
microsoftofficeMatch2003sp2
OR
microsoftofficeMatch2003sp3
OR
microsoftworksMatch8.0
OR
microsoftworksMatch2005

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.951 High

EPSS

Percentile

99.3%