[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-3858Date: (C)2013-09-11   (M)2023-12-22


Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3847, CVE-2013-3848, and CVE-2013-3849.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
MS13-067
MS13-072
TA13-253A
oval:org.mitre.oval:def:18709
oval:org.mitre.oval:def:18801

CPE    8
cpe:/a:microsoft:word:2003:sp3
cpe:/a:microsoft:word:2010:sp1:~~~~x64~
cpe:/a:microsoft:sharepoint_server:2010:sp1
cpe:/a:microsoft:word_viewer
...
CWE    1
CWE-119
OVAL    4
oval:org.secpod.oval:def:15680
oval:org.secpod.oval:def:15438
oval:org.secpod.oval:def:15439
oval:org.secpod.oval:def:15677
...

© SecPod Technologies