5.1
CVSSv2

CVE-2006-3493

Published: 10/07/2006 Updated: 30/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted malicious users to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft office 2000

microsoft office 2003

microsoft office xp

Exploits

/*------------------------------------------------------------ * Microsoft Word unchecked boundary condition vulnerability * --------------------------------------------------------- * One of the functions in msodll (older versions mso9dll) * cannot properly handle the specially crafted files causing * invalid memory acess and ...