Vulnerabilities > Microsoft > Visual Studio > 6.0

DATE CVE VULNERABILITY TITLE RISK
2014-05-20 CVE-2014-3802 Improper Input Validation vulnerability in Microsoft products
msdia.dll in Microsoft Debug Interface Access (DIA) SDK, as distributed in Microsoft Visual Studio before 2013, does not properly validate an unspecified variable before use in calculating a dynamic-call address, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDB file.
network
microsoft CWE-20
6.8
2008-08-18 CVE-2008-3704 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft products
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability." Additional advisory information from Secunia: http://secunia.com/advisories/31498/ "Visual Studio 6 was last updated June 2000, a Microsoft spokeswoman told SCMagazineUS.com.
network
microsoft CWE-119
critical
9.3
2007-09-14 CVE-2007-4891 OS Command Injection vulnerability in Microsoft Visual Studio 6.0/6.0.0.9782
A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote attackers to execute arbitrary programs and have other impacts, as demonstrated using absolute pathnames in arguments to StartProcess and SyncShell.
network
microsoft CWE-78
6.8
2007-09-14 CVE-2007-4890 Path Traversal vulnerability in Microsoft Visual Studio 6.0
Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1.0.0.0 in Microsoft Visual Studio 6.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveAs method.
network
microsoft CWE-22
5.8
2007-08-08 CVE-2007-4254 Remote Security vulnerability in Microsoft products
Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Designer 7.0 for Microsoft Visual Studio 6 allows remote attackers to execute arbitrary code via a long argument to the NotSafe method.
network
microsoft
6.8
2007-01-24 CVE-2007-0468 Remote Security vulnerability in Microsoft Visual Studio 6.0
Stack-based buffer overflow in rcdll.dll in msdev.exe in Visual C++ (MSVC) in Microsoft Visual Studio 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a long file path in the "1 TYPELIB MOVEABLE PURE" option in an RC file.
network
microsoft
6.8
2006-08-31 CVE-2006-4494 Denial of Service vulnerability in Microsoft Visual Studio 6.0
Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Visual Studio 6.0 ActiveX COM Objects in Internet Explorer, including (1) tcprops.dll, (2) fp30wec.dll, (3) mdt2db.dll, (4) mdt2qd.dll, and (5) vi30aut.dll.
network
low complexity
microsoft
7.5
2006-03-07 CVE-2006-1043 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Visual Interdev and Visual Studio
Stack-based buffer overflow in Microsoft Visual Studio 6.0 and Microsoft Visual InterDev 6.0 allows user-assisted attackers to execute arbitrary code via a long DataProject field in a (1) Visual Studio Database Project File (.dbp) or (2) Visual Studio Solution (.sln).
network
high complexity
microsoft CWE-119
5.1
2001-05-03 CVE-2001-0153 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Visual Basic and Visual Studio
Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands.
network
low complexity
microsoft CWE-119
7.5
2000-02-18 CVE-2000-0162 Unspecified vulnerability in Microsoft IE, Internet Explorer and Visual Studio
The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability.
network
high complexity
microsoft
5.1