Lucene search

K
cveMicrosoftCVE-2010-3214
HistoryOct 13, 2010 - 7:00 p.m.

CVE-2010-3214

2010-10-1319:00:44
CWE-119
microsoft
web.nvd.nist.gov
45
cve-2010-3214
microsoft word
buffer overflow
remote code execution
security vulnerability
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

Low

EPSS

0.9

Percentile

98.9%

Stack-based buffer overflow in Microsoft Word 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; Word Viewer; Office Web Apps; and Word Web App allows remote attackers to execute arbitrary code via a crafted Word document, aka β€œWord Stack Overflow Vulnerability.”

Affected configurations

Nvd
Node
microsoftofficeMatch2004mac
OR
microsoftofficeMatch2008mac
OR
microsoftoffice_compatibility_packMatch2007sp2
OR
microsoftoffice_web_apps
OR
microsoftopen_xml_file_format_convertermac
OR
microsoftwordMatch2002sp3
OR
microsoftwordMatch2003sp3
OR
microsoftwordMatch2007sp2
OR
microsoftwordMatch2010x32
OR
microsoftwordMatch2010x64
OR
microsoftword_viewer
OR
microsoftword_web_app
VendorProductVersionCPE
microsoftoffice2004cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*
microsoftoffice2008cpe:2.3:a:microsoft:office:2008:*:mac:*:*:*:*:*
microsoftoffice_compatibility_pack2007cpe:2.3:a:microsoft:office_compatibility_pack:2007:sp2:*:*:*:*:*:*
microsoftoffice_web_apps*cpe:2.3:a:microsoft:office_web_apps:*:*:*:*:*:*:*:*
microsoftopen_xml_file_format_converter*cpe:2.3:a:microsoft:open_xml_file_format_converter:*:*:mac:*:*:*:*:*
microsoftword2002cpe:2.3:a:microsoft:word:2002:sp3:*:*:*:*:*:*
microsoftword2003cpe:2.3:a:microsoft:word:2003:sp3:*:*:*:*:*:*
microsoftword2007cpe:2.3:a:microsoft:word:2007:sp2:*:*:*:*:*:*
microsoftword2010cpe:2.3:a:microsoft:word:2010:*:x32:*:*:*:*:*
microsoftword2010cpe:2.3:a:microsoft:word:2010:*:x64:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

Low

EPSS

0.9

Percentile

98.9%