Vulnerabilities > Microsoft > Office > 2007.sp1

DATE CVE VULNERABILITY TITLE RISK
2008-05-13 CVE-2008-1434 Resource Management Errors vulnerability in Microsoft products
Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) selectors, related to a "memory handling error" that triggers memory corruption.
network
microsoft CWE-399
critical
9.3
2008-05-13 CVE-2008-1091 Code Injection vulnerability in Microsoft products
Unspecified vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via a Rich Text Format (.rtf) file with a malformed string that triggers a "memory calculation error" and a heap-based buffer overflow, aka "Object Parsing Vulnerability."
network
microsoft CWE-94
critical
9.3
2008-05-13 CVE-2008-0119 Code Injection vulnerability in Microsoft Office
Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka "Publisher Object Handler Validation Vulnerability."
network
microsoft CWE-94
critical
9.3
2008-04-08 CVE-2008-1090 Resource Management Errors vulnerability in Microsoft Office and Visio
Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a crafted .DXF file, aka "Visio Memory Validation Vulnerability."
network
microsoft CWE-399
critical
9.3
2008-04-08 CVE-2008-1089 Code Injection vulnerability in Microsoft Office and Visio
Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka "Visio Object Header Vulnerability."
network
microsoft CWE-94
critical
9.3