9.3

CVE-2009-1534

Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Visual Studio .NET 2003 SP1 allows remote attackers to execute arbitrary code via crafted property values, aka "Office Web Components Buffer Overflow Vulnerability."

Data is provided by the National Vulnerability Database (NVD)
MicrosoftIsa Server Version2004 Updatesp3 Editionenterprise
   MicrosoftIsa Server Version2004 Updatesp3 Editionenterprise
   MicrosoftIsa Server Version2004 Updatesp3 Editionenterprise
MicrosoftIsa Server Version2004 Updatesp3 Editionstandard
   MicrosoftIsa Server Version2004 Updatesp3 Editionstandard
   MicrosoftIsa Server Version2004 Updatesp3 Editionstandard
MicrosoftIsa Server Version2006 Updatesp1 Editionenterprise
   MicrosoftIsa Server Version2006 Updatesp1 Editionenterprise
   MicrosoftIsa Server Version2006 Updatesp1 Editionenterprise
MicrosoftIsa Server Version2006 Updatesp1 Editionstandard
   MicrosoftIsa Server Version2006 Updatesp1 Editionstandard
   MicrosoftIsa Server Version2006 Updatesp1 Editionstandard
MicrosoftOffice Version- Editionsmall_business_accounting_2006
   MicrosoftOffice Version- Editionsmall_business_accounting_2006
   MicrosoftOffice Version- Editionsmall_business_accounting_2006
MicrosoftOffice Version2003 Updatesp3
   MicrosoftOffice Version2003 Updatesp3
   MicrosoftOffice Version2003 Updatesp3
MicrosoftOffice Versionxp Updatesp3
   MicrosoftOffice Versionxp Updatesp3
   MicrosoftOffice Versionxp Updatesp3
MicrosoftOffice Web Components Version2000 Updatesp3
   MicrosoftOffice Web Components Version2000 Updatesp3
   MicrosoftOffice Web Components Version2000 Updatesp3
MicrosoftOffice Web Components Version2003 Updatesp1 Edition2007_microsoft_office
   MicrosoftOffice Web Components Version2003 Updatesp1 Edition2007_microsoft_office
   MicrosoftOffice Web Components Version2003 Updatesp1 Edition2007_microsoft_office
MicrosoftOffice Web Components Version2003 Updatesp3
   MicrosoftOffice Web Components Version2003 Updatesp3
   MicrosoftOffice Web Components Version2003 Updatesp3
MicrosoftOffice Web Components Versionxp Updatesp3
   MicrosoftOffice Web Components Versionxp Updatesp3
   MicrosoftOffice Web Components Versionxp Updatesp3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 75.43% 0.988
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.