← All CVEs

CVE-2010-0264

high · 9.3

Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."

9.3
CVSS
21.2%
EPSS (exploit prob.)
97th
EPSS percentile
2010-03-10
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
microsoftexcel2002
microsoftexcel2003
microsoftexcel2007
microsoftexcel2007
microsoftoffice2004
microsoftoffice2008
microsoftoffice_compatibility_pack2007
microsoftoffice_compatibility_pack2007
microsoftoffice_excel_viewerall versions
microsoftoffice_excel_viewerall versions
microsoftoffice_sharepoint_server2007
microsoftoffice_sharepoint_server2007
microsoftoffice_sharepoint_server2007
microsoftoffice_sharepoint_server2007
microsoftopen_xml_file_format_converterall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-0264