Lucene search

K
nvd[email protected]NVD:CVE-2009-2518
HistoryOct 14, 2009 - 10:30 a.m.

CVE-2009-2518

2009-10-1410:30:01
CWE-189
web.nvd.nist.gov
2

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.132 Low

EPSS

Percentile

95.6%

Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office document with a bitmap (aka BMP) image that triggers memory corruption, aka β€œOffice BMP Integer Overflow Vulnerability.”

Affected configurations

NVD
Node
microsoftofficeMatchxpsp3

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.132 Low

EPSS

Percentile

95.6%