CVE-2011-1982
high · 9.3Microsoft Office 2007 SP2, and 2010 Gold and SP1, does not initialize an unspecified object pointer during the opening of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Office Uninitialized Object Pointer Vulnerability."
9.3
CVSS
27.7%
EPSS (exploit prob.)
98th
EPSS percentile
2011-09-15
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | office | 2007 |
| microsoft | office | 2010 |
| microsoft | office | 2010 |
| microsoft | office | 2010 |
| microsoft | office | 2010 |
Check a specific version with /api/v1/cve/match.
References
- http://www.kb.cert.org/vuls/id/909022
- http://www.us-cert.gov/cas/techalerts/TA11-256A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-073
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12243
- http://www.kb.cert.org/vuls/id/909022
- http://www.us-cert.gov/cas/techalerts/TA11-256A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-073
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12243
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-1982