Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
7.5
CVE-2002-0727
- EPSS 9.52%
- Veröffentlicht 24.09.2002 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.
- EPSS 31.69%
- Veröffentlicht 24.09.2002 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.
7.5
CVE-2002-0861
- EPSS 6.15%
- Veröffentlicht 24.09.2002 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object.