Vulnerabilities > Microsoft > Excel > 2004

DATE CVE VULNERABILITY TITLE RISK
2009-02-25 CVE-2009-0238 Code Injection vulnerability in Microsoft products
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.
network
microsoft CWE-94
critical
9.3
2007-08-14 CVE-2007-3890 Remote Code Execution vulnerability in Microsoft Excel and Office
Microsoft Excel in Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a Workspace with a certain index value that triggers memory corruption.
network
microsoft
critical
9.3
2007-07-10 CVE-2007-3030 Remote Code Execution vulnerability in Microsoft Excel Workspace Designation
Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file involving the "denoting [of] the start of a Workspace designation", which results in memory corruption, aka the "Workbook Memory Corruption Vulnerability".
network
high complexity
microsoft
7.6
2007-05-08 CVE-2007-1214 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Excel and Excel Viewer
Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted AutoFilter filter record in an Excel BIFF8 format XLS file, which triggers memory corruption.
network
microsoft CWE-119
6.8
2007-05-08 CVE-2007-1203 Remote Code Execution vulnerability in Microsoft Excel Set Font
Unspecified vulnerability in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a crafted set font value in an Excel file, which results in memory corruption.
network
microsoft
critical
9.3
2007-02-03 CVE-2007-0671 Remote Code Execution vulnerability in Microsoft Office Malformed String
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
network
microsoft
critical
9.3
2006-10-10 CVE-2006-3875 Remote Code Execution vulnerability in Microsoft Excel COLINFO
Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted COLINFO record in an XLS file, a different vulnerability than CVE-2006-2387 and CVE-2006-3867.
network
high complexity
microsoft
5.1
2006-10-10 CVE-2006-3867 Remote Code Execution vulnerability in Microsoft Excel Lotus 1-2-3 File Handling
Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted Lotus 1-2-3 file, a different vulnerability than CVE-2006-2387 and CVE-2006-3875.
network
high complexity
microsoft
5.1
2006-07-13 CVE-2006-1309 Code Injection vulnerability in Microsoft Excel and Excel Viewer
Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.
network
microsoft CWE-94
critical
9.3
2006-07-13 CVE-2006-1308 Remote Code Execution vulnerability in Microsoft Excel FNGROUPCOUNT Record
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.
network
microsoft
critical
9.3