Vulnerabilities > Microsoft > Powerpoint

DATE CVE VULNERABILITY TITLE RISK
2009-05-12 CVE-2009-0224 Code Injection vulnerability in Microsoft products
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; PowerPoint Viewer 2003 and 2007 SP1 and SP2; PowerPoint in Microsoft Office 2004 for Mac and 2008 for Mac; Open XML File Format Converter for Mac; Microsoft Works 8.5 and 9.0; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly validate PowerPoint files, which allows remote attackers to execute arbitrary code via multiple crafted BuildList records that include ChartBuild containers, which triggers memory corruption, aka "Memory Corruption Vulnerability."
network
microsoft CWE-94
critical
9.3
2009-04-03 CVE-2009-0556 Code Injection vulnerability in Microsoft Office Powerpoint and Powerpoint
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."
network
microsoft CWE-94
critical
9.3
2008-07-07 CVE-2008-3068 Remote Information Disclosure vulnerability in Microsoft Crypto API X.509 Certificate Validation
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
network
low complexity
microsoft
7.5
2007-02-14 CVE-2007-0913 Remote Security vulnerability in PowerPoint
Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as exploited by Trojan.PPDropper.G.
network
microsoft
critical
9.3
2007-02-03 CVE-2007-0671 Remote Code Execution vulnerability in Microsoft Office Malformed String
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
network
microsoft
critical
9.3
2006-10-16 CVE-2006-5296 Remote Denial of Service vulnerability in Microsoft Powerpoint 2003
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694.
network
microsoft
4.3
2006-10-10 CVE-2006-3877 Code Injection vulnerability in Microsoft products
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
network
microsoft CWE-94
critical
9.3
2006-08-09 CVE-2006-3449 Remote Code Execution vulnerability in Microsoft Powerpoint
Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, possibly a buffer overflow, allows user-assisted remote attackers to execute arbitrary commands via a malformed record in the BIFF file format used in a PPT file, a different issue than CVE-2006-1540, aka "Microsoft PowerPoint Malformed Record Vulnerability."
network
low complexity
microsoft
7.5
2006-07-18 CVE-2006-3660 Multiple Unspecified vulnerability in Microsoft Powerpoint 2003
Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe.
network
high complexity
microsoft
7.6
2006-07-18 CVE-2006-3656 Multiple Unspecified vulnerability in Microsoft Powerpoint 2003
Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed.
network
high complexity
microsoft
2.6