Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2009-0088 | First vendor Publication | 2009-04-15 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka "Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0088 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-20 | Improper Input Validation |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:5736 | |||
Oval ID: | oval:org.mitre.oval:def:5736 | ||
Title: | Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability | ||
Description: | The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka "Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2009-0088 | Version: | 7 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista | Product(s): | Microsoft Word 2000 Microsoft Office Converter Pack |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 | |
Application | 2 | |
Os | 1 | |
Os | 4 | |
Os | 4 |
OpenVAS Exploits
Date | Description |
---|---|
2008-12-12 | Name : WordPad and Office Text Converter Memory Corruption Vulnerability (960477) File : nvt/secpod_ms_wordpad_mult_vuln.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
53663 | Microsoft Office Word 2000 WordPerfect 6.x Converter Document Handling Stack ... |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2009-04-16 | IAVM : 2009-A-0032 - Multiple Vulnerabilities in WordPad and Office Text Converters Severity : Category I - VMSKEY : V0018752 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-06-19 | Microsoft Office Word WordPerfect converter buffer overflow attempt RuleID : 31032 - Revision : 2 - Type : FILE-OFFICE |
2014-06-19 | Microsoft Office Word WordPerfect converter buffer overflow attempt RuleID : 31031 - Revision : 2 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office WordPad and Office text converters integer underflow attempt RuleID : 23557 - Revision : 5 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office WordPad and Office text converters integer underflow attempt RuleID : 23556 - Revision : 5 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office WordPad and Office text converters integer underflow attempt RuleID : 23356 - Revision : 5 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office Word Converter XST structure buffer overflow attempt RuleID : 17406 - Revision : 10 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office Word Converter XST structure buffer overflow attempt RuleID : 17405 - Revision : 11 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office Word Converter XST structure buffer overflow attempt RuleID : 17404 - Revision : 13 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office WordPad and Office text converters integer underflow attempt RuleID : 15469 - Revision : 17 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office WordPad and Office Text Converters PlcPcd aCP buffer overflo... RuleID : 15467 - Revision : 17 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office WordPad WordPerfect 6.x converter buffer overflow attempt RuleID : 15466 - Revision : 13 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office WordPad and Office Text Converters XST parsing buffer overfl... RuleID : 15455 - Revision : 9 - Type : FILE-OFFICE |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2009-04-15 | Name : It is possible to execute arbitrary code on the remote Windows host using a t... File : smb_nt_ms09-010.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:11:36 |
|
2024-11-28 12:18:03 |
|
2020-05-23 00:23:12 |
|
2019-02-26 17:19:31 |
|
2018-10-13 00:22:46 |
|
2017-09-29 09:24:01 |
|
2016-06-28 17:33:20 |
|
2016-04-26 18:33:02 |
|
2014-06-19 21:24:43 |
|
2014-02-17 10:48:16 |
|
2014-01-19 21:25:33 |
|
2013-11-11 12:38:09 |
|
2013-05-10 23:41:48 |
|