Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-3477
Description:Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index errors, and memory corruption, aka "Calendar Object Validation Vulnerability."
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-3477
BugTraq ID: 31702
http://www.securityfocus.com/bid/31702
Cert/CC Advisory: TA08-288A
http://www.us-cert.gov/cas/techalerts/TA08-288A.html
HPdes Security Advisory: HPSBST02379
http://marc.info/?l=bugtraq&m=122479227205998&w=2
HPdes Security Advisory: SSRT080143
http://marc.info/?l=bugtraq&m=122479227205998&w=2
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=746
Microsoft Security Bulletin: MS08-057
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-057
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5870
http://www.securitytracker.com/id?1021044
http://secunia.com/advisories/32211
http://www.vupen.com/english/advisories/2008/2808
XForce ISS Database: excel-calendar-code-execution(45566)
https://exchange.xforce.ibmcloud.com/vulnerabilities/45566
XForce ISS Database: win-ms08kb956416-update(45581)
https://exchange.xforce.ibmcloud.com/vulnerabilities/45581




© 1998-2025 E-Soft Inc. All rights reserved.