Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2006-3493


Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.


Published

2006-07-10T22:05:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

4.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microsoft office 2000 Yes
Application microsoft office 2000 Yes
Application microsoft office 2000 Yes
Application microsoft office 2000 Yes
Application microsoft office 2003 Yes
Application microsoft office 2003 Yes
Application microsoft office 2003 Yes
Application microsoft office 2003 Yes
Application microsoft office xp Yes
Application microsoft office xp Yes
Application microsoft office xp Yes
Application microsoft office xp Yes

References