Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-0252 | First vendor Publication | 2010-02-10 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The Microsoft Data Analyzer ActiveX control (aka the Office Excel ActiveX control for Data Analysis) in max3activex.dll in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted web page that corrupts the "system state," aka "Microsoft Data Analyzer ActiveX Control Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0252 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
OVAL Definitions
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2011-04-13 | Name : Microsoft IE Developer Tools WMITools and Windows Messenger ActiveX Control V... File : nvt/secpod_ms11-027.nasl |
2010-06-15 | Name : Computer Associates WebScan ActiveX Control Multiple Remote Code Execution Vu... File : nvt/gb_ca_activex_mult_code_exec_vuln.nasl |
2010-06-09 | Name : Microsoft Windows Kernel Mode Drivers Privilege Escalation Vulnerabilities (9... File : nvt/secpod_ms10-032.nasl |
2010-06-09 | Name : Microsoft Data Analyzer and IE Developer Tools ActiveX Control Vulnerability ... File : nvt/secpod_ms10-034.nasl |
2010-02-10 | Name : Microsoft SMB Client Remote Code Execution Vulnerabilities (978251) File : nvt/secpod_ms10-006.nasl |
2010-02-10 | Name : Microsoft Data Analyzer ActiveX Control Vulnerability (978262) File : nvt/secpod_ms10-008.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
62246 | Microsoft Data Analyzer ActiveX Web Page Handling Unspecified Arbitrary Code ... |
Snort® IPS/IDS
Date | Description |
---|---|
2020-03-19 | Microsoft Windows Data Analyzer 3.5 ActiveX clsid access RuleID : 53118 - Revision : 1 - Type : BROWSER-PLUGINS |
2020-03-19 | Microsoft Windows Data Analyzer 3.5 ActiveX use-after-free attempt RuleID : 53117 - Revision : 1 - Type : BROWSER-PLUGINS |
2020-03-19 | Microsoft Windows Data Analyzer 3.5 ActiveX use-after-free attempt RuleID : 53116 - Revision : 1 - Type : BROWSER-PLUGINS |
2015-01-20 | Microsoft Internet Explorer 8 Developer Tool ActiveX clsid access RuleID : 32843 - Revision : 3 - Type : BROWSER-PLUGINS |
2014-01-10 | Symantec WinFax Pro ActiveX heap buffer overflow attempt RuleID : 27208 - Revision : 4 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Internet Explorer 8 Developer Tool ActiveX clsid access RuleID : 16635 - Revision : 13 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Data Analyzer 3.5 ActiveX clsid unicode access RuleID : 16420 - Revision : 5 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Windows Data Analyzer 3.5 ActiveX clsid access RuleID : 16419 - Revision : 15 - Type : BROWSER-PLUGINS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-06-09 | Name : The remote Windows host is missing an update that disables selected ActiveX c... File : smb_nt_ms10-034.nasl - Type : ACT_GATHER_INFO |
2010-02-09 | Name : The remote Windows host is missing an update that disables selected ActiveX c... File : smb_nt_ms10-008.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:09:25 |
|
2024-11-28 12:21:00 |
|
2024-08-02 12:13:02 |
|
2024-08-02 01:03:31 |
|
2024-02-02 01:12:32 |
|
2024-02-01 12:03:28 |
|
2023-12-07 21:28:04 |
|
2023-09-05 12:11:45 |
|
2023-09-05 01:03:19 |
|
2023-09-02 12:11:48 |
|
2023-09-02 01:03:21 |
|
2023-08-12 12:13:59 |
|
2023-08-12 01:03:20 |
|
2023-08-11 12:11:51 |
|
2023-08-11 01:03:29 |
|
2023-08-06 12:11:24 |
|
2023-08-06 01:03:23 |
|
2023-08-04 12:11:29 |
|
2023-08-04 01:03:24 |
|
2023-07-14 12:11:25 |
|
2023-07-14 01:03:22 |
|
2023-03-29 01:13:06 |
|
2023-03-28 12:03:28 |
|
2022-10-11 12:10:11 |
|
2022-10-11 01:03:10 |
|
2021-05-04 12:11:00 |
|
2021-04-22 01:11:34 |
|
2020-05-23 00:25:09 |
|
2018-10-31 00:20:02 |
|
2018-10-13 00:22:54 |
|
2018-09-20 12:08:15 |
|
2017-09-19 09:23:37 |
|
2016-09-30 01:02:18 |
|
2016-08-31 12:02:02 |
|
2016-08-05 12:02:23 |
|
2016-06-28 18:00:32 |
|
2016-04-26 19:31:41 |
|
2014-02-17 10:53:29 |
|
2014-01-19 21:26:33 |
|
2013-05-10 23:16:55 |
|