Vulnerabilities > Microsoft > Office > 2000

DATE CVE VULNERABILITY TITLE RISK
2008-02-12 CVE-2008-0109 Resource Management Errors vulnerability in Microsoft Office and Word
Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.
network
microsoft CWE-399
critical
9.3
2008-02-12 CVE-2008-0104 Code Injection vulnerability in Microsoft Office and Publisher
Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, aka "Publisher Memory Corruption Vulnerability."
network
microsoft CWE-94
critical
9.3
2007-10-09 CVE-2007-3899 Code Injection vulnerability in Microsoft Office and Word
Unspecified vulnerability in Microsoft Word 2000 SP3, Word 2002 SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string in a Word file, aka "Word Memory Corruption Vulnerability."
network
microsoft CWE-94
critical
9.3
2007-08-14 CVE-2007-3890 Remote Code Execution vulnerability in Microsoft Excel and Office
Microsoft Excel in Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a Workspace with a certain index value that triggers memory corruption.
network
microsoft
critical
9.3
2007-07-10 CVE-2007-1756 Remote Code Execution vulnerability in Microsoft Excel, Excel Viewer and Office
Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and Office Excel 2007 does not properly validate version information, which allows user-assisted remote attackers to execute arbitrary code via a crafted Excel file, aka "Calculation Error Vulnerability".
network
microsoft
critical
9.3
2007-05-30 CVE-2007-2903 Buffer Overflow vulnerability in Microsoft Office 2000
Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument.
network
low complexity
microsoft
5.0
2007-05-08 CVE-2007-1747 Resource Management Errors vulnerability in Microsoft Office
Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a malformed drawing object, which triggers memory corruption.
network
microsoft CWE-399
critical
9.3
2007-05-08 CVE-2007-0215 Remote Code Execution vulnerability in Microsoft Excel, Excel Viewer and Office
Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption.
network
high complexity
microsoft
7.6
2007-05-08 CVE-2007-0035 Improper Input Validation vulnerability in Microsoft Office and Works
Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly handle data in a certain array, which allows user-assisted remote attackers to execute arbitrary code, aka the "Word Array Overflow Vulnerability."
network
microsoft CWE-20
critical
9.3
2007-02-13 CVE-2007-0209 Code Injection vulnerability in Microsoft Office and Works
Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.
network
microsoft CWE-94
critical
9.3