Vulnerabilities > CVE-2008-2752 - Resource Management Errors vulnerability in Microsoft Word 2000/2003
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
COMPLETE Summary
Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 does not properly handle unordered lists, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .doc file. NOTE: some of these details are obtained from third party information.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 9 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | Microsoft Word 2000/2002 Bulleted List Handling Remote Memory Corruption Vulnerability. CVE-2008-2752. Dos exploit for windows platform |
id | EDB-ID:31934 |
last seen | 2016-02-03 |
modified | 2008-06-17 |
published | 2008-06-17 |
reporter | Ivan Sanchez |
source | https://www.exploit-db.com/download/31934/ |
title | Microsoft Word 2000/2002 - Bulleted List Handling Remote Memory Corruption Vulnerability |
References
- http://www.nullcode.com.ar/ncs/crash/video.htm
- http://www.nullcode.com.ar/ncs/crash/video2.htm
- http://www.securityfocus.com/bid/29769
- http://www.securityfocus.com/data/vulnerabilities/exploits/crash-word-1.doc
- http://www.securityfocus.com/data/vulnerabilities/exploits/crash-word-2.doc
- http://www.securityfocus.com/data/vulnerabilities/exploits/crash-word-3.doc
- http://www.securityfocus.com/data/vulnerabilities/exploits/crash-word-4.doc
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43155