[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-1311Date: (C)2007-02-13   (M)2024-03-01


The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Office 2004 for Mac; and Learning Essentials for Microsoft Office 1.0, 1.1, and 1.5 allows user-assisted remote attackers to execute arbitrary code via a malformed OLE object in an RTF file, which triggers memory corruption.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1017640
SECTRACK-1017641
BID-21876
SECUNIA-24152
OSVDB-31886
ADV-2007-0582
MS07-013
TA07-044A
VU#368132
ms-richedit-code-execution(30592)
oval:org.mitre.oval:def:1090

CPE    8
cpe:/a:microsoft:office:2000:sp3
cpe:/a:microsoft:office
cpe:/a:microsoft:office:xp:sp3
cpe:/a:microsoft:learning_essentials:1.5
...
OVAL    1
oval:org.mitre.oval:def:1090

© SecPod Technologies