oval:org.mitre.oval:def:15462

Definition Id: oval:org.mitre.oval:def:15462
 
Oval ID: oval:org.mitre.oval:def:15462
Title: MSCOMCTL.OCX RCE Vulnerability
Description: The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers "system state" corruption, as exploited in the wild in April 2012, aka "MSCOMCTL.OCX RCE Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2012-0158
Version: 10
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows 7
Product(s): Microsoft Office 2003
Microsoft Office 2003 Web Components
Microsoft Office 2007
Microsoft Office 2010
Microsoft SQL Server 2000 Analysis Services
Microsoft SQL Server 2000
Microsoft SQL Server 2005 Express Edition
Microsoft SQL Server 2005
Microsoft SQL Server 2008
Microsoft SQL Server 2008 R2
Microsoft BizTalk Server 2002
Microsoft Commerce Server 2002
Microsoft Commerce Server 2007
Microsoft Commerce Server 2009
Microsoft Commerce Server 2009 R2
Microsoft Visual FoxPro 8.0
Microsoft Visual FoxPro 9.0
Visual Basic 6.0 Runtime
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:233
 
Oval ID: oval:org.mitre.oval:def:233
Title: Microsoft Office 2003 is installed
Description: The application Microsoft Office 2003 is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:office:2003
Version: 10
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Product(s): Microsoft Office 2003
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15626
Definition Id: oval:org.mitre.oval:def:1211
 
Oval ID: oval:org.mitre.oval:def:1211
Title: Microsoft Office 2007 is installed
Description: The application Microsoft Office 2007 is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:office:2007
Version: 10
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Product(s): Microsoft Office 2007
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15704
oval:org.mitre.oval:def:15607
Definition Id: oval:org.mitre.oval:def:6189
 
Oval ID: oval:org.mitre.oval:def:6189
Title: Microsoft Office 2003 Web Components is installed
Description: The application Microsoft Office 2003 Web Components is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:office_web_components:2003
Version: 1
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15325
Definition Id: oval:org.mitre.oval:def:14198
 
Oval ID: oval:org.mitre.oval:def:14198
Title: Microsoft Visual FoxPro is installed
Description: Microsoft Visual FoxPro is installed
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:visual_foxpro
Version: 3
Platform(s): Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s): Microsoft Visual FoxPro
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:15369
 
Oval ID: oval:org.mitre.oval:def:15369
Title: Microsoft Visual Basic 6.0 is installed
Description: The application Microsoft Visual Basic 6.0 is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:visual_basic:6.0
Version: 5
Platform(s): Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s): Microsoft Visual Basic 6.0
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:15626
 
Oval ID: oval:org.mitre.oval:def:15626
Title: Microsoft Office 2003 SP3 is installed
Description: Microsoft Office 2003 SP3 is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:office:2003:sp3
Version: 5
Platform(s): Microsoft Windows 7
Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s): Microsoft Office 2003
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:15704
 
Oval ID: oval:org.mitre.oval:def:15704
Title: Microsoft Office 2007 SP3 is installed
Description: Microsoft Office 2007 SP3 is installed
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:office:2007:sp3
Version: 7
Platform(s): Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s): Microsoft Office 2007
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:17121
 
Oval ID: oval:org.mitre.oval:def:17121
Title: Microsoft Office 2010 SP2 is installed
Description: Microsoft Office 2010 SP2 is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:office:2010:sp2
Version: 9
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows Server 2012
Product(s): Microsoft Office 2010
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:15198
 
Oval ID: oval:org.mitre.oval:def:15198
Title: Microsoft Office 2010 SP1 is installed
Description: Microsoft Office 2010 SP1 is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:office:2010:sp1
Version: 15
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows Server 2012
Product(s): Microsoft Office 2010
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:12061
 
Oval ID: oval:org.mitre.oval:def:12061
Title: Microsoft Office 2010 is installed
Description: The application Microsoft Office 2010 is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:office:2010
Version: 13
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows 7
Microsoft Windows Server 2008 R2
Microsoft Windows 8
Microsoft Windows Server 2012
Product(s): Microsoft Office 2010
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
oval:org.mitre.oval:def:17121
oval:org.mitre.oval:def:15198
oval:org.mitre.oval:def:20819
Definition Id: oval:org.mitre.oval:def:20819
 
Oval ID: oval:org.mitre.oval:def:20819
Title: Microsoft Office 2010 SP1 x86 is installed
Description: Microsoft Office 2010 SP1 x86 is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:office:2010:sp1:x86
Version: 5
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows Server 2012
Product(s): Microsoft Office 2010
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:12454
 
Oval ID: oval:org.mitre.oval:def:12454
Title: Microsoft SQL Server 2008 is installed
Description: Microsoft SQL Server 2008 is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:sql_server:2008
Version: 19
Platform(s): Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s): Microsoft SQL Server 2008
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15497
Definition Id: oval:org.mitre.oval:def:12596
 
Oval ID: oval:org.mitre.oval:def:12596
Title: Microsoft SQL Server 2008 R2 is installed
Description: Microsoft SQL Server 2008 R2 is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:sql_server:2008:r2
Version: 11
Platform(s): Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s): Microsoft SQL Server 2008 R2
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
oval:org.mitre.oval:def:15803
Definition Id: oval:org.mitre.oval:def:15607
 
Oval ID: oval:org.mitre.oval:def:15607
Title: Microsoft Office 2007 SP2 is installed
Description: Microsoft Office 2007 SP2 is installed
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:office:2007:sp2
Version: 9
Platform(s): Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s): Microsoft Office 2007
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:15292
 
Oval ID: oval:org.mitre.oval:def:15292
Title: Microsoft BizTalk Server 2002 is installed
Description: The application Microsoft BizTalk Server 2002 is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:biztalk_server:2002
Version: 3
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Product(s): Microsoft BizTalk Server 2002
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:15304
 
Oval ID: oval:org.mitre.oval:def:15304
Title: Microsoft Commerce Server 2002 is installed
Description: The application Microsoft Commerce Server 2002 is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:commerce_server:2002
Version: 5
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Product(s): Microsoft Commerce Server 2002
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:15514
 
Oval ID: oval:org.mitre.oval:def:15514
Title: Microsoft Commerce Server 2007 is installed
Description: The application Microsoft Commerce Server 2007 is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:commerce_server:2007
Version: 5
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Product(s): Microsoft Commerce Server 2007
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:15443
 
Oval ID: oval:org.mitre.oval:def:15443
Title: Microsoft Commerce Server 2009 is installed
Description: The application Microsoft Commerce Server 2009 is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:commerce_server:2009
Version: 5
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Product(s): Microsoft Commerce Server 2009
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:15490
 
Oval ID: oval:org.mitre.oval:def:15490
Title: Microsoft SQL Server 2000 Analysis Services is installed
Description: The application Microsoft SQL Server 2000 Analysis Services is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:sql_server_analysis_services:2000
Version: 3
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Product(s): Microsoft SQL Server 2000 Analysis Services
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15730
Definition Id: oval:org.mitre.oval:def:15325
 
Oval ID: oval:org.mitre.oval:def:15325
Title: Microsoft Office 2003 Web Components SP3 is installed
Description: Microsoft Office 2003 Web Components SP3 is installed
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:office_web_components:2003:sp3
Version: 5
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Product(s): Microsoft Office 2003 Web Components
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:15497
 
Oval ID: oval:org.mitre.oval:def:15497
Title: Microsoft SQL Server 2008 SP3 is installed
Description: Microsoft SQL Server 2008 SP3 is installed
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:sql_server:2008:sp3
Version: 17
Platform(s): Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s): Microsoft SQL Server 2008
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:12310
 
Oval ID: oval:org.mitre.oval:def:12310
Title: Microsoft SQL Server 2008 SP2 is installed
Description: Microsoft SQL Server 2008 SP2 is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:sql_server:2008:sp2
Version: 15
Platform(s): Microsoft Windows Server 2003
Microsoft Windows Server 2008
Product(s): Microsoft SQL Server 2008
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:15803
 
Oval ID: oval:org.mitre.oval:def:15803
Title: Microsoft SQL Server 2008 R2 SP2 is installed
Description: Microsoft SQL Server 2008 R2 SP2 is installed
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:sql_server:2008_r2:sp2
Version: 9
Platform(s): Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s): Microsoft SQL Server 2008 R2
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:12442
 
Oval ID: oval:org.mitre.oval:def:12442
Title: Microsoft SQL Server 2005 SP4 is installed
Description: Microsoft SQL Server 2005 SP4 is installed.
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:sql_server:2005:sp4
Version: 15
Platform(s): Microsoft Windows Server 2003
Microsoft Windows Server 2008
Product(s): Microsoft SQL Server 2005
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:15730
 
Oval ID: oval:org.mitre.oval:def:15730
Title: Microsoft SQL Server 2000 Analysis Services SP4 is installed
Description: Microsoft SQL Server 2000 Analysis Services SP4 is installed
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:sql_server:2000:sp4:analysis_services
Version: 3
Platform(s): Microsoft Windows Server 2003
Microsoft Windows 2000
Microsoft Windows XP
Product(s): Microsoft SQL Server 2000 Analysis Services
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:15762
 
Oval ID: oval:org.mitre.oval:def:15762
Title: Microsoft SQL Server 2000 SP4 is installed
Description: Microsoft SQL Server 2000 SP4 is installed
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:sql_server:2000:sp4
Version: 3
Platform(s): Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s): Microsoft SQL Server 2000
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15462
Definition Id: oval:org.mitre.oval:def:14854
 
Oval ID: oval:org.mitre.oval:def:14854
Title: Microsoft SQL Server 2000 is installed
Description: Microsoft SQL Server 2000 is installed
Family: windows Class: inventory
Reference(s): cpe:/a:microsoft:sql_server:2000
Version: 3
Platform(s): Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s): Microsoft SQL Server 2000
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:15762