Vulnerabilities > Microsoft > Excel > 2002

DATE CVE VULNERABILITY TITLE RISK
2006-07-13 CVE-2006-1309 Code Injection vulnerability in Microsoft Excel and Excel Viewer
Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.
network
microsoft CWE-94
critical
9.3
2006-07-13 CVE-2006-1308 Remote Code Execution vulnerability in Microsoft Excel FNGROUPCOUNT Record
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.
network
microsoft
critical
9.3
2006-07-13 CVE-2006-1301 Code Injection vulnerability in Microsoft Excel and Excel Viewer
Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.
network
microsoft CWE-94
critical
9.3
2006-07-13 CVE-2006-2388 Code Injection vulnerability in Microsoft Excel and Excel Viewer
Microsoft Office Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via malformed cell comments, which lead to modification of "critical data offsets" during the rebuilding process.
network
microsoft CWE-94
critical
9.3
2006-07-13 CVE-2006-1306 Code Injection vulnerability in Microsoft Excel and Excel Viewer
Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka "Malformed OBJECT record Vulnerability."
network
microsoft CWE-94
critical
9.3
2006-07-13 CVE-2006-1304 Code Injection vulnerability in Microsoft Excel and Excel Viewer
Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."
network
microsoft CWE-94
critical
9.3
2006-07-13 CVE-2006-1302 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Excel and Excel Viewer
Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerability."
network
microsoft CWE-119
critical
9.3
2006-06-17 CVE-2006-3059 Remote Code Execution vulnerability in Microsoft Excel
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors.
network
microsoft
critical
9.3
2006-03-14 CVE-2006-0030 Unspecified vulnerability in Microsoft Excel and Office
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.
network
high complexity
microsoft
5.1
2006-03-14 CVE-2006-0029 Unspecified vulnerability in Microsoft Excel and Office
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.
network
high complexity
microsoft
5.1