Vulnerability Name: | CVE-2004-0848 (CCN-19107) | ||||||||||||||||
Assigned: | 2004-09-08 | ||||||||||||||||
Published: | 2005-02-08 | ||||||||||||||||
Updated: | 2018-10-12 | ||||||||||||||||
Summary: | Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames. | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2004-0848 Source: CCN Type: CIAC Information Bulletin P-130 Microsoft Vulnerability in Microsoft Office XP Source: CCN Type: US-CERT VU#416001 Microsoft Office XP contains buffer overflow vulnerability Source: CERT-VN Type: Patch, Third Party Advisory, US Government Resource VU#416001 Source: CCN Type: Microsoft Security Bulletin MS05-005 Vulnerability in Microsoft Office XP could lead to Buffer Overrun (873352) Source: CCN Type: BID-12480 Microsoft Office XP HTML Link Processing Remote Buffer Overflow Vulnerability Source: CERT Type: Patch, Third Party Advisory, US Government Resource TA05-039A Source: MS Type: UNKNOWN MS05-005 Source: XF Type: UNKNOWN ms-url-bo(19107) Source: XF Type: UNKNOWN ms-url-bo(19107) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:2348 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:2738 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:4022 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |