← All CVEs

CVE-2006-3435

high · 9.3

PowerPoint in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac does not properly parse the slide notes field in a document, which allows remote user-assisted attackers to execute arbitrary code via crafted data in this field, which triggers an erroneous object pointer calculation that uses data from within the document. NOTE: this issue is different than other PowerPoint vulnerabilities including CVE-2006-4694.

9.3
CVSS
37.4%
EPSS (exploit prob.)
98th
EPSS percentile
2006-10-10
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
microsoftoffice2000
microsoftoffice2000
microsoftoffice2000
microsoftoffice2000
microsoftoffice2003
microsoftoffice2003
microsoftoffice2003
microsoftoffice2003
microsoftoffice2004
microsoftofficev.x
microsoftofficexp
microsoftofficexp
microsoftofficexp
microsoftofficexp

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-3435