Lucene search

K
cve[email protected]CVE-2008-3460
HistoryAug 12, 2008 - 11:41 p.m.

CVE-2008-3460

2008-08-1223:41:00
CWE-399
web.nvd.nist.gov
32
cve-2008-3460
microsoft office
remote code execution
wpg image file heap corruption vulnerability
security vulnerability

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.716 High

EPSS

Percentile

98.1%

WPGIMP32.FLT in Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 does not properly parse the length of a WordPerfect Graphics (WPG) file, which allows remote attackers to execute arbitrary code via a crafted WPG file, aka the “WPG Image File Heap Corruption Vulnerability.”

Affected configurations

NVD
Node
microsoftofficeMatch2000sp3
OR
microsoftofficeMatch2003sp2
OR
microsoftofficeMatchxpsp3
OR
microsoftoffice_converter_pack
OR
microsoftworksMatch8.0

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.716 High

EPSS

Percentile

98.1%