7.5

CVE-2004-0848

Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftOffice Versionxp Updatesp1
MicrosoftOffice Versionxp Updatesp2
MicrosoftOffice Versionxp Updatesp3
MicrosoftPowerpoint Version2002
MicrosoftPowerpoint Version2002 Updatesp1
MicrosoftPowerpoint Version2002 Updatesp2
MicrosoftPowerpoint Version2002 Updatesp3
MicrosoftProject Version2002
MicrosoftProject Version2002 Updatesp1
MicrosoftVisio Version2002
MicrosoftVisio Version2002 Updatesp1
MicrosoftVisio Version2002 Updatesp2
MicrosoftVisio Version2002 Updatesp2 Editionprofessional
MicrosoftVisio Version2002 Updatesp2 Editionstandard
MicrosoftWord Version2002
MicrosoftWord Version2002 Updatesp1
MicrosoftWord Version2002 Updatesp2
MicrosoftWord Version2002 Updatesp3
MicrosoftWorks Version2002
MicrosoftWorks Version2003
MicrosoftWorks Version2004
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 42.12% 0.973
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P