Lucene search

K
cve[email protected]CVE-2008-1090
HistoryApr 08, 2008 - 11:05 p.m.

CVE-2008-1090

2008-04-0823:05:00
CWE-399
web.nvd.nist.gov
62
cve-2008-1090
microsoft visio
remote code execution
memory validation
dxf file

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.595 Medium

EPSS

Percentile

97.8%

Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a crafted .DXF file, aka β€œVisio Memory Validation Vulnerability.”

Affected configurations

NVD
Node
microsoftofficeMatch2003sp2
OR
microsoftofficeMatch2003sp3
OR
microsoftofficeMatch2007
OR
microsoftofficeMatch2007_sp1
OR
microsoftofficeMatchxpsp2
OR
microsoftvisioMatch2002sp2
OR
microsoftvisioMatch2003sp1
OR
microsoftvisioMatch2003_sp3
OR
microsoftvisioMatch2007
OR
microsoftvisioMatch2007_sp1

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.595 Medium

EPSS

Percentile

97.8%