René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

121 lines
3.9 KiB
JSON

{
"id": "CVE-2008-0105",
"sourceIdentifier": "secure@microsoft.com",
"published": "2008-02-12T23:00:00.000",
"lastModified": "2018-10-12T21:44:51.193",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka \"Microsoft Works File Converter Index Table Vulnerability.\""
},
{
"lang": "es",
"value": "Microsoft Works 6 File Converter, como el utilizado en Office 2003 SP2 y SP3, Works 8.0, y Works Suite 2005, permite a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n a trav\u00e9s de un fichero .wps con una secci\u00f3n de la cabecera de \u00edndice de la tabla de informaci\u00f3n manipulada, tambi\u00e9n conocida como \"Vulnerabilidad en Tabla \u00cdndice de Microsoft Works File Converter\""
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 9.3
},
"baseSeverity": "HIGH",
"exploitabilityScore": 8.6,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": true,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*",
"matchCriteriaId": "07D3F3E4-93FB-481A-94D9-075E726697C4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*",
"matchCriteriaId": "A332D04D-CC8C-4F68-A261-BA2F2D8EAD1E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:works:8.0:*:*:*:*:*:*:*",
"matchCriteriaId": "293914AF-6101-4F50-9560-A4EA99D767C4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:works:2005:*:*:*:*:*:*:*",
"matchCriteriaId": "CB8E7A05-97EE-40A4-A410-B2DE582AA381"
}
]
}
]
}
],
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=120361015026386&w=2",
"source": "secure@microsoft.com"
},
{
"url": "http://www.securityfocus.com/bid/27658",
"source": "secure@microsoft.com"
},
{
"url": "http://www.securitytracker.com/id?1019387",
"source": "secure@microsoft.com"
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA08-043C.html",
"source": "secure@microsoft.com",
"tags": [
"US Government Resource"
]
},
{
"url": "http://www.vupen.com/english/advisories/2008/0513/references",
"source": "secure@microsoft.com"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-011",
"source": "secure@microsoft.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5009",
"source": "secure@microsoft.com"
}
]
}