CVE-2009-2528
14.10.2009, 10:30
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."
Vendor | Product | Version |
---|---|---|
microsoft | windows_2003_server | * |
microsoft | windows_2003_server | * |
microsoft | windows_2003_server | * |
microsoft | windows_server_2008 | * |
microsoft | windows_server_2008 | * |
microsoft | windows_server_2008 | * |
microsoft | windows_vista | * |
microsoft | windows_vista | * |
microsoft | windows_vista | * |
microsoft | windows_xp | * |
microsoft | windows_xp | * |
microsoft | windows_xp | * |
microsoft | .net_framework | 1.1:sp1 |
microsoft | .net_framework | 2.0:sp1 |
microsoft | .net_framework | 2.0:sp2 |
microsoft | expression_web | * |
microsoft | office_excel_viewer | * |
microsoft | office_powerpoint_viewer | * |
microsoft | office_word_viewer | * |
microsoft | works | 8.5 |
microsoft | platform_sdk | * |
microsoft | forefront_client_security | 1.0 |
microsoft | visual_foxpro | 8.0:sp1 |
microsoft | visual_foxpro | 9.0:sp2 |
𝑥
= Vulnerable software versions
References