CVE-2013-3854
- EPSS 52.85%
- Veröffentlicht 11.09.2013 14:03:48
- Zuletzt bearbeitet 11.04.2025 00:51:21
Microsoft Office 2007 SP3 and Word 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CV...
CVE-2013-3859
- EPSS 0.46%
- Veröffentlicht 11.09.2013 14:03:48
- Zuletzt bearbeitet 11.04.2025 00:51:21
Microsoft Pinyin IME 2010, when used in conjunction with Microsoft Office 2010 SP1, does not properly restrict configuration options, which allows local users to gain privileges by starting Internet Explorer from the IME toolbar, aka "Chinese IME Vul...
CVE-2013-3129
- EPSS 46.52%
- Veröffentlicht 10.07.2013 03:46:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Serv...
CVE-2013-1331
- EPSS 85.15%
- Veröffentlicht 12.06.2013 03:29:57
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."
- EPSS 29.25%
- Veröffentlicht 13.03.2013 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 ele...
CVE-2013-0006
- EPSS 65.08%
- Veröffentlicht 09.01.2013 18:09:40
- Zuletzt bearbeitet 11.04.2025 00:51:21
Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."
CVE-2013-0007
- EPSS 27.2%
- Veröffentlicht 09.01.2013 18:09:40
- Zuletzt bearbeitet 11.04.2025 00:51:21
Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML XSLT Vulnerability."
CVE-2012-1885
- EPSS 65.94%
- Veröffentlicht 14.11.2012 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Office 2008 and 2011 for Mac; and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Se...
CVE-2012-1887
- EPSS 58.33%
- Veröffentlicht 14.11.2012 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1, and Office 2008 and 2011 for Mac, allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SST Invalid Length Use After Free Vuln...
CVE-2012-2543
- EPSS 65.94%
- Veröffentlicht 14.11.2012 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 SP1; Office 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Stack O...