Lucene search

K
cve[email protected]CVE-2008-4019
HistoryOct 15, 2008 - 12:12 a.m.

CVE-2008-4019

2008-10-1500:12:15
CWE-190
web.nvd.nist.gov
44
cve-2008-4019
integer overflow
microsoft excel
nvd
remote code execution
formula parsing vulnerability

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.892 High

EPSS

Percentile

98.8%

Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office SharePoint Server 2007 Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file containing a formula within a cell, aka β€œFormula Parsing Vulnerability.”

Affected configurations

NVD
Node
microsoftexcelMatch2003sp2
OR
microsoftexcelMatch2003sp3
OR
microsoftexcelMatch2007-
OR
microsoftexcelMatch2007sp1
OR
microsoftexcel_viewerMatch-
OR
microsoftexcel_viewerMatch2003-
OR
microsoftexcel_viewerMatch2003sp3
OR
microsoftofficeMatch2004macos
OR
microsoftofficeMatch2008macos
OR
microsoftoffice_compatibility_packMatch2007-
OR
microsoftoffice_compatibility_packMatch2007sp1
OR
microsoftopen_xml_file_format_converterMatch-macos
OR
microsoftsharepoint_serverMatch2007x64
OR
microsoftsharepoint_serverMatch2007-
OR
microsoftsharepoint_serverMatch2007sp1
OR
microsoftsharepoint_serverMatch2007sp1x64

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.892 High

EPSS

Percentile

98.8%