CVE Vulnerabilities

CVE-2008-1434

Published: May 13, 2008 | Modified: Oct 12, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) selectors, related to a memory handling error that triggers memory corruption.

Affected Software

Name Vendor Start Version End Version
Office Microsoft 2000-sp3 (including) 2000-sp3 (including)
Office Microsoft 2003-sp2 (including) 2003-sp2 (including)
Office Microsoft 2003-sp3 (including) 2003-sp3 (including)
Office Microsoft 2004 (including) 2004 (including)
Office Microsoft 2007 (including) 2007 (including)
Office Microsoft 2007_sp1 (including) 2007_sp1 (including)
Office Microsoft 2008 (including) 2008 (including)
Office Microsoft xp-sp3 (including) xp-sp3 (including)
Office_compatibility_pack_for_word_excel_ppt_2007 Microsoft * *
Word_viewer Microsoft 2003 (including) 2003 (including)

References