Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2008-1455


A "memory calculation error" in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP2, and 2007 through SP1; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 through SP1; and Office 2004 for Mac allows remote attackers to execute arbitrary code via a PowerPoint file with crafted list values that trigger memory corruption, aka "Parsing Overflow Vulnerability."


Published

2008-08-13T00:41:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-399

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microsoft compatibility_pack_word_excel_powerpoint 2007 Yes
Application microsoft compatibility_pack_word_excel_powerpoint 2007 Yes
Application microsoft office 2000 Yes
Application microsoft office 2003 Yes
Application microsoft office 2003 Yes
Application microsoft office 2004 Yes
Application microsoft office 2007 Yes
Application microsoft office 2007 Yes
Application microsoft office xp Yes
Application microsoft office_powerpoint_viewer 2003 Yes

References