Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2009-0235 | First vendor Publication | 2009-04-15 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corruption, related to use of inconsistent integer data sizes for an unspecified length field, aka "WordPad Word 97 Text Converter Stack Overflow Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0235 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:5893 | |||
Oval ID: | oval:org.mitre.oval:def:5893 | ||
Title: | WordPad Word 97 Text Converter Stack Overflow Vulnerability | ||
Description: | Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corruption, related to use of inconsistent integer data sizes for an unspecified length field, aka "WordPad Word 97 Text Converter Stack Overflow Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2009-0235 | Version: | 6 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 1 | |
Os | 2 | |
Os | 2 |
SAINT Exploits
Description | Link |
---|---|
Microsoft WordPad Word97 text converter buffer overflow | More info here |
OpenVAS Exploits
Date | Description |
---|---|
2008-12-12 | Name : WordPad and Office Text Converter Memory Corruption Vulnerability (960477) File : nvt/secpod_ms_wordpad_mult_vuln.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
53664 | Microsoft WordPad Word 97 Text Converter File Handling Overflow |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2009-04-16 | IAVM : 2009-A-0032 - Multiple Vulnerabilities in WordPad and Office Text Converters Severity : Category I - VMSKEY : V0018752 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-06-19 | Microsoft Office Word WordPerfect converter buffer overflow attempt RuleID : 31032 - Revision : 2 - Type : FILE-OFFICE |
2014-06-19 | Microsoft Office Word WordPerfect converter buffer overflow attempt RuleID : 31031 - Revision : 2 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office WordPad and Office text converters integer underflow attempt RuleID : 23557 - Revision : 5 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office WordPad and Office text converters integer underflow attempt RuleID : 23556 - Revision : 5 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office WordPad and Office text converters integer underflow attempt RuleID : 23356 - Revision : 5 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office Word Converter XST structure buffer overflow attempt RuleID : 17406 - Revision : 10 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office Word Converter XST structure buffer overflow attempt RuleID : 17405 - Revision : 11 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office Word Converter XST structure buffer overflow attempt RuleID : 17404 - Revision : 13 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office WordPad and Office text converters integer underflow attempt RuleID : 15469 - Revision : 17 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office WordPad and Office Text Converters PlcPcd aCP buffer overflo... RuleID : 15467 - Revision : 17 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office WordPad WordPerfect 6.x converter buffer overflow attempt RuleID : 15466 - Revision : 13 - Type : FILE-OFFICE |
2014-01-10 | Microsoft Office WordPad and Office Text Converters XST parsing buffer overfl... RuleID : 15455 - Revision : 9 - Type : FILE-OFFICE |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2009-04-15 | Name : It is possible to execute arbitrary code on the remote Windows host using a t... File : smb_nt_ms09-010.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:11:36 |
|
2024-11-28 12:18:08 |
|
2021-05-04 12:09:02 |
|
2021-04-22 01:09:23 |
|
2020-05-23 00:23:15 |
|
2018-10-13 00:22:46 |
|
2017-09-29 09:24:02 |
|
2016-06-28 17:33:57 |
|
2016-04-26 18:34:28 |
|
2014-02-17 10:48:30 |
|
2014-01-19 21:25:38 |
|
2013-11-11 12:38:12 |
|
2013-05-10 23:42:52 |
|