CVE-2008-1434

Severity

93%

Complexity

86%

Confidentiality

165%

Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) selectors, related to a "memory handling error" that triggers memory corruption.

Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) selectors, related to a "memory handling error" that triggers memory corruption.

CVSS 2.0 Base Score 9.3. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).

Overview

Type

Microsoft

First reported 16 years ago

2008-05-13 22:20:00

Last updated 6 years ago

2018-10-12 21:45:00

Affected Software

Microsoft Office 2000 sp3

2000

Microsoft Office 2003 sp2

2003

Microsoft Office 2003 Service Pack 3

2003

Microsoft Office 2004 Mac

2004

Microsoft Office 2007

2007

Microsoft Office 2008 Mac

2008

Microsoft Office XP Service Pack 3

xp

Microsoft Word Viewer 2003

2003

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.