Lucene search

K
nvd[email protected]NVD:CVE-2010-0256
HistoryApr 14, 2010 - 4:00 p.m.

CVE-2010-0256

2010-04-1416:00:01
CWE-94
web.nvd.nist.gov
2

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.423

Percentile

97.3%

Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly calculate unspecified indexes associated with Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka “Visio Index Calculation Memory Corruption Vulnerability.”

Affected configurations

Nvd
Node
microsoftvisioMatch2002sp2
OR
microsoftvisioMatch2003sp3
OR
microsoftvisioMatch2007sp1
OR
microsoftvisioMatch2007sp2
VendorProductVersionCPE
microsoftvisio2002cpe:2.3:a:microsoft:visio:2002:sp2:*:*:*:*:*:*
microsoftvisio2003cpe:2.3:a:microsoft:visio:2003:sp3:*:*:*:*:*:*
microsoftvisio2007cpe:2.3:a:microsoft:visio:2007:sp1:*:*:*:*:*:*
microsoftvisio2007cpe:2.3:a:microsoft:visio:2007:sp2:*:*:*:*:*:*

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.423

Percentile

97.3%