Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2003-0347

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2003-0347
Last Modified 05 Sep 2008 04:34:06
Published 20 Oct 2003 12:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2003-0347

Summary

Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.

Vulnerable Systems

Application

  • Microsoft Office 2000

  • Microsoft Office Xp

  • Microsoft Project 2000

  • Microsoft Project 2002

  • Microsoft Visio 2002

  • Microsoft Visual Basic 5.0

  • Microsoft Visual Basic 6.2

  • Microsoft Visual Basic 6.3


References

CERT-VN - VU#804780

BID - 8534

MS - MS03-037

SECUNIA - 9666

BUGTRAQ - 20030903 EEYE: VBE Document Property Buffer Overflow


Last Updated: 27 May 2016 10:37:52