Vulnerabilities > Microsoft > Excel > 2002

DATE CVE VULNERABILITY TITLE RISK
2010-06-08 CVE-2010-1253 Code Injection vulnerability in Microsoft products
Microsoft Office Excel 2002 SP3, 2007 SP1, and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to execute arbitrary code via an Excel file with crafted DBQueryExt records that allow a function call to a "user-controlled pointer," aka "Excel ADO Object Vulnerability."
network
microsoft CWE-94
critical
9.3
2010-06-08 CVE-2010-1252 Code Injection vulnerability in Microsoft Excel and Office
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."
network
microsoft CWE-94
critical
9.3
2010-06-08 CVE-2010-1251 Code Injection vulnerability in Microsoft Excel and Office
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel Record Stack Corruption Vulnerability."
network
microsoft CWE-94
critical
9.3
2010-06-08 CVE-2010-1250 Code Injection vulnerability in Microsoft Excel, Office and Open XML File Format Converter
Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with malformed (1) EDG (0x88) and (2) Publisher (0x89) records, aka "Excel EDG Memory Corruption Vulnerability."
network
microsoft CWE-94
critical
9.3
2010-06-08 CVE-2010-1249 Code Injection vulnerability in Microsoft Excel, Office and Open XML File Format Converter
Buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed ExternName (0x23) record, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1247.
network
microsoft CWE-94
critical
9.3
2010-06-08 CVE-2010-1248 Code Injection vulnerability in Microsoft Excel and Office
Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed HFPicture (0x866) record, aka "Excel HFPicture Memory Corruption Vulnerability."
network
microsoft CWE-94
critical
9.3
2010-06-08 CVE-2010-1247 Code Injection vulnerability in Microsoft Excel 2002
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record that triggers heap corruption, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1249.
network
microsoft CWE-94
critical
9.3
2010-06-08 CVE-2010-1246 Code Injection vulnerability in Microsoft Excel 2002
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record, aka "Excel RTD Memory Corruption Vulnerability."
network
microsoft CWE-94
critical
9.3
2010-06-08 CVE-2010-1245 Code Injection vulnerability in Microsoft Excel, Office and Open XML File Format Converter
Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed SxView (0xB0) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0824 and CVE-2010-0821.
network
microsoft CWE-94
critical
9.3
2010-06-08 CVE-2010-0824 Code Injection vulnerability in Microsoft Excel and Office
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed WOPT (0x80B) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0821 and CVE-2010-1245.
network
microsoft CWE-94
critical
9.3