Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2006-3449


Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, possibly a buffer overflow, allows user-assisted remote attackers to execute arbitrary commands via a malformed record in the BIFF file format used in a PPT file, a different issue than CVE-2006-1540, aka "Microsoft PowerPoint Malformed Record Vulnerability."


Published

2006-08-09T00:04:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microsoft powerpoint 2000 Yes
Application microsoft powerpoint 2000 Yes
Application microsoft powerpoint 2000 Yes
Application microsoft powerpoint 2000 Yes
Application microsoft powerpoint 2000 Yes
Application microsoft powerpoint 2000 Yes
Application microsoft powerpoint 2000 Yes
Application microsoft powerpoint 2001 Yes
Application microsoft powerpoint 2002 Yes
Application microsoft powerpoint 2002 Yes
Application microsoft powerpoint 2002 Yes
Application microsoft powerpoint 2002 Yes
Application microsoft powerpoint 2003 Yes

References