CVE-2009-0558
high · 9.3Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Array Indexing Memory Corruption Vulnerability."
9.3
CVSS
31.1%
EPSS (exploit prob.)
98th
EPSS percentile
2009-06-10
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | office | 2004 |
| microsoft | office | 2008 |
| microsoft | office | xp |
| microsoft | office_compatibility_pack_for_word_excel_ppt_2007 | all versions |
| microsoft | office_compatibility_pack_for_word_excel_ppt_2007 | all versions |
| microsoft | office_excel | 2000 |
| microsoft | office_excel | 2003 |
| microsoft | office_excel | 2007 |
| microsoft | office_excel | 2007 |
| microsoft | office_excel_viewer | all versions |
| microsoft | office_excel_viewer | 2003 |
| microsoft | office_sharepoint_server | 2007 |
| microsoft | office_sharepoint_server | 2007 |
| microsoft | office_sharepoint_server | 2007 |
| microsoft | office_sharepoint_server | 2007 |
| microsoft | open_xml_file_format_converter | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/54954
- http://secunia.com/secunia_research/2009-1/
- http://www.securityfocus.com/archive/1/504188/100/0/threaded
- http://www.securityfocus.com/bid/35242
- http://www.securitytracker.com/id?1022351
- http://www.us-cert.gov/cas/techalerts/TA09-160A.html
- http://www.vupen.com/english/advisories/2009/1540
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-021
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11525
- http://osvdb.org/54954
- http://secunia.com/secunia_research/2009-1/
- http://www.securityfocus.com/archive/1/504188/100/0/threaded
- http://www.securityfocus.com/bid/35242
- http://www.securitytracker.com/id?1022351
- http://www.us-cert.gov/cas/techalerts/TA09-160A.html
- http://www.vupen.com/english/advisories/2009/1540
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-021
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11525
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2009-0558