Microsoft

Project

30 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 45.71%
  • Published 10.10.2006 22:07:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file...

Exploit
  • EPSS 44.57%
  • Published 19.08.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for...

  • EPSS 42.12%
  • Published 08.02.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.

  • EPSS 76.69%
  • Published 28.09.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to...

Exploit
  • EPSS 70.46%
  • Published 20.10.2003 04:00:00
  • Last modified 03.04.2025 01:03:51

Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.

  • EPSS 6.15%
  • Published 24.09.2002 04:00:00
  • Last modified 03.04.2025 01:03:51

Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object.

  • EPSS 24.97%
  • Published 24.09.2002 04:00:00
  • Last modified 03.04.2025 01:03:51

The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.

  • EPSS 9.52%
  • Published 24.09.2002 04:00:00
  • Last modified 03.04.2025 01:03:51

The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.

  • EPSS 10.95%
  • Published 11.05.2000 04:00:00
  • Last modified 03.04.2025 01:03:51

The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.

  • EPSS 0.59%
  • Published 01.01.1999 05:00:00
  • Last modified 03.04.2025 01:03:51

The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.