← All CVEs

CVE-2006-3864

high · 9.3

Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file that triggers memory corruption, related to an "array boundary condition" (possibly an array index overflow), a different vulnerability than CVE-2006-3434, CVE-2006-3650, and CVE-2006-3868.

9.3
CVSS
34.0%
EPSS (exploit prob.)
98th
EPSS percentile
2006-10-10
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
microsoftoffice2000
microsoftoffice2003
microsoftoffice2003
microsoftoffice2004
microsoftofficev.x
microsoftofficexp
microsoftproject2000
microsoftproject2002
microsoftvisio2002

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-3864