Vulnerabilities > Microsoft > Office Compatibility Pack FOR Word Excel PPT 2007 > Critical

DATE CVE VULNERABILITY TITLE RISK
2008-05-13 CVE-2008-1434 Resource Management Errors vulnerability in Microsoft products
Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) selectors, related to a "memory handling error" that triggers memory corruption.
network
microsoft CWE-399
critical
9.3
2008-03-11 CVE-2008-0111 Code Injection vulnerability in Microsoft products
Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted data validation records, aka "Excel Data Validation Record Vulnerability."
network
microsoft CWE-94
critical
9.3
2008-03-11 CVE-2008-0115 Code Injection vulnerability in Microsoft products
Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via malformed formulas, aka "Excel Formula Parsing Vulnerability."
network
microsoft CWE-94
critical
9.3
2008-03-11 CVE-2008-0116 Improper Input Validation vulnerability in Microsoft products
Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to execute arbitrary code via malformed tags in rich text, aka "Excel Rich Text Validation Vulnerability."
network
microsoft CWE-20
critical
9.3