Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-2752

Overview

Vulnerability Score 7.1 7.1
CVE Id CVE-2008-2752
Last Modified 10 Sep 2008 09:11:18
Published 18 Jun 2008 03:41:00
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-2752

Summary

Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 does not properly handle unordered lists, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .doc file. NOTE: some of these details are obtained from third party information.

Vulnerable Systems

Application

  • Microsoft Word 2000

  • Microsoft Word 2003


References

XF - microsoft-word-unorderedlist-code-execution(43155)

MISC - http://www.securityfocus.com/data/vulnerabilities/exploits/crash-word-4.doc

MISC - http://www.securityfocus.com/data/vulnerabilities/exploits/crash-word-3.doc

MISC - http://www.securityfocus.com/data/vulnerabilities/exploits/crash-word-2.doc

MISC - http://www.securityfocus.com/data/vulnerabilities/exploits/crash-word-1.doc

BID - 29769


Last Updated: 27 May 2016 10:47:58