CVE-2011-1972
- EPSS 61.03%
- Published 10.08.2011 21:55:01
- Last modified 11.04.2025 00:51:21
Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "pStream Release RCE Vulnerability."
CVE-2011-0093
- EPSS 44.03%
- Published 10.02.2011 16:00:31
- Last modified 11.04.2025 00:51:21
ELEMENTS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 does not properly parse structures during the opening of a Visio file, which allows remote attackers to execute arbitrary code via a file containing a malformed structure, aka "Visio Da...
CVE-2011-0092
- EPSS 44.59%
- Published 10.02.2011 16:00:31
- Last modified 11.04.2025 00:51:21
The LZW stream decompression functionality in ORMELEMS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 allows remote attackers to execute arbitrary code via a Visio file with a malformed VisioDocument stream that triggers an exception handler...
CVE-2010-3148
- EPSS 26.53%
- Published 27.08.2010 19:00:18
- Last modified 11.04.2025 00:51:21
Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .vsd, .vdx, .vst, or .vtx file...
CVE-2010-1681
- EPSS 79.08%
- Published 06.05.2010 12:47:23
- Last modified 11.04.2025 00:51:21
Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary code via a crafted DXF file, a different vulnerability than CVE-2010-0254 and CVE-2010-0256.
CVE-2010-0254
- EPSS 20.48%
- Published 14.04.2010 16:00:01
- Last modified 11.04.2025 00:51:21
Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Attribute Validation Memory Corruption Vulner...
CVE-2010-0256
- EPSS 20.48%
- Published 14.04.2010 16:00:01
- Last modified 11.04.2025 00:51:21
Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly calculate unspecified indexes associated with Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Index Calculation Memo...
CVE-2009-3126
- EPSS 50.94%
- Published 14.10.2009 10:30:01
- Last modified 09.04.2025 00:30:58
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP...
CVE-2009-2528
- EPSS 41.2%
- Published 14.10.2009 10:30:01
- Last modified 09.04.2025 00:30:58
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vu...
CVE-2009-2504
- EPSS 48.8%
- Published 14.10.2009 10:30:01
- Last modified 09.04.2025 00:30:58
Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Mi...