Lucene search

K
cve[email protected]CVE-2008-0120
HistoryAug 13, 2008 - 12:41 a.m.

CVE-2008-0120

2008-08-1300:41:00
CWE-399
web.nvd.nist.gov
31
4
cve-2008-0120
integer overflow
microsoft powerpoint viewer 2003
remote code execution
memory corruption
cstring objects
memory allocation vulnerability
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.687 Medium

EPSS

Percentile

98.0%

Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka β€œMemory Allocation Vulnerability.”

Affected configurations

NVD
Node
microsoftoffice_powerpoint_viewerMatch2003

Social References

More

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.687 Medium

EPSS

Percentile

98.0%