Vulnerabilities > Microsoft > Critical

DATE CVE VULNERABILITY TITLE RISK
2008-08-12 CVE-2008-3018 Code Injection vulnerability in Microsoft Office, Office Converter Pack and Works
Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows remote attackers to execute arbitrary code via a crafted PICT file, aka the "Malformed PICT Filter Vulnerability," a different vulnerability than CVE-2008-3021.
network
microsoft CWE-94
critical
9.3
2008-08-12 CVE-2008-3006 Resource Management Errors vulnerability in Microsoft products
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 Gold and SP3; Office Excel Viewer; Office Compatibility Pack 2007 Gold and SP1; Office SharePoint Server 2007 Gold and SP1; and Office 2004 and 2008 for Mac do not properly parse Country record values when loading Excel files, which allows remote attackers to execute arbitrary code via a crafted Excel file, aka the "Excel Record Parsing Vulnerability." This vulnerability has multiple attack vectors and CIA impact.
network
microsoft CWE-399
critical
9.3
2008-08-12 CVE-2008-3005 Improper Input Validation vulnerability in Microsoft Office
Array index vulnerability in Microsoft Office Excel 2000 SP3 and 2002 SP3, and Office 2004 and 2008 for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted array index for a FORMAT record, aka the "Excel Index Array Vulnerability."
network
microsoft CWE-20
critical
9.3
2008-08-12 CVE-2008-3004 Improper Input Validation vulnerability in Microsoft Office and Office Excel Viewer
Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3; Office Excel Viewer 2003; and Office 2004 and 2008 for Mac do not properly validate index values for AxesSet records when loading Excel files, which allows remote attackers to execute arbitrary code via a crafted Excel file, aka the "Excel Indexing Validation Vulnerability."
network
microsoft CWE-20
critical
9.3
2008-07-09 CVE-2008-2244 Resource Management Errors vulnerability in Microsoft Office Word 2002
Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July 2008, and as demonstrated by attachement.doc.
network
microsoft CWE-399
critical
9.3
2008-07-09 CVE-2008-3079 Remote Security vulnerability in Opera
Unspecified vulnerability in Opera before 9.51 on Windows allows attackers to execute arbitrary code via unknown vectors.
network
low complexity
microsoft opera
critical
10.0
2008-07-08 CVE-2008-1454 Unspecified vulnerability in Microsoft products
Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 allows remote attackers to conduct cache poisoning attacks via unknown vectors related to accepting "records from a response that is outside the remote server's authority," aka "DNS Cache Poisoning Vulnerability," a different vulnerability than CVE-2008-1447.
network
low complexity
microsoft
critical
9.4
2008-07-08 CVE-2008-1435 Code Injection vulnerability in Microsoft Windows-Nt and Windows Vista
Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary code via crafted saved-search (.search-ms) files that are not properly handled when saving, aka "Windows Saved Search Vulnerability."
network
microsoft CWE-94
critical
9.3
2008-07-08 CVE-2008-0107 Numeric Errors vulnerability in Microsoft products
Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 allows remote authenticated users to execute arbitrary code via a (1) SMB or (2) WebDAV pathname for an on-disk file (aka stored backup file) with a crafted record size value, which triggers a heap-based buffer overflow, aka "SQL Server Memory Corruption Vulnerability."
network
low complexity
microsoft CWE-189
critical
9.0
2008-07-08 CVE-2008-0106 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft products
Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement.
network
low complexity
microsoft CWE-119
critical
9.0