Vulnerabilities > Microsoft > Wordpad

DATE CVE VULNERABILITY TITLE RISK
2009-12-09 CVE-2009-2506 Numeric Errors vulnerability in Microsoft products
Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a DOC file with an invalid number of property names in the DocumentSummaryInformation stream, which triggers a heap-based buffer overflow.
network
microsoft CWE-189
critical
9.3
2008-12-10 CVE-2008-4841 Resource Management Errors vulnerability in Microsoft Wordpad Unknown
The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008.
network
microsoft CWE-399
critical
9.3