René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

151 lines
5.5 KiB
JSON

{
"id": "CVE-2008-4256",
"sourceIdentifier": "secure@microsoft.com",
"published": "2008-12-10T14:00:00.987",
"lastModified": "2018-10-12T21:48:47.813",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the \"system state,\" aka \"Charts Control Memory Corruption Vulnerability.\""
},
{
"lang": "es",
"value": "El control ActiveX Charts en Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 y 2003 SP1, y Visual FoxPro 8.0 SP1 y 9.0 SP1 y SP2 no maneja adecuadamente errores durante el acceso de objetos inicializados incorrectamente, lo que permite a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n a trav\u00e9s de documentos HTML manipulados, relacionados con la corrupci\u00f3n del \"estado del sistema,\" tambi\u00e9n conocido como vulnerabilidad de corrupci\u00f3n de memoria en el control de caracteres.\""
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:S/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "SINGLE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 8.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 6.8,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-399"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office_frontpage:2002:sp3:*:*:*:*:*:*",
"matchCriteriaId": "F2D429D9-577E-4CD6-ADEC-1119B60DB20F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:project:2003:sp3:*:*:*:*:*:*",
"matchCriteriaId": "25881D4B-06E5-4083-AEEF-B6E1CE5C459A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:project:2007:*:*:*:*:*:*:*",
"matchCriteriaId": "9CD3B021-8145-49FA-8809-C3976ED1BE62"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:project:2007:sp1:*:*:*:*:*:*",
"matchCriteriaId": "145E1D64-840B-4AE8-91CB-EA4884ED51D4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visual_basic:6.0:*:runtime_extended_files:*:*:*:*:*",
"matchCriteriaId": "DD65D7E8-016B-44EC-A416-E9247810CFF3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visual_foxpro:8.0:sp1:*:*:*:*:*:*",
"matchCriteriaId": "E5DE8B76-FA09-4EA2-9535-758C56C4C099"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visual_foxpro:9.0:sp1:*:*:*:*:*:*",
"matchCriteriaId": "478347F8-6256-4DE6-AD6A-91631A9E6DD1"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visual_foxpro:9.0:sp2:*:*:*:*:*:*",
"matchCriteriaId": "5E711CC3-9094-4C54-A794-9C7A3E7F4AFA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visual_studio_.net:2002:sp1:*:*:*:*:*:*",
"matchCriteriaId": "747E3E3A-85C1-4E55-B7F8-C5207F247498"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visual_studio_.net:2003:sp1:*:*:*:*:*:*",
"matchCriteriaId": "85959AEB-2FE5-4A25-B298-F8223CE260D6"
}
]
}
]
}
],
"references": [
{
"url": "http://support.avaya.com/elmodocs2/security/ASA-2008-473.htm",
"source": "secure@microsoft.com"
},
{
"url": "http://www.securityfocus.com/bid/32614",
"source": "secure@microsoft.com"
},
{
"url": "http://www.securitytracker.com/id?1021369",
"source": "secure@microsoft.com"
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA08-344A.html",
"source": "secure@microsoft.com",
"tags": [
"US Government Resource"
]
},
{
"url": "http://www.vupen.com/english/advisories/2008/3382",
"source": "secure@microsoft.com"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-070",
"source": "secure@microsoft.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5651",
"source": "secure@microsoft.com"
}
]
}