CVE detail
CVE-2006-3864
Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file that triggers memory corruption, related to an "array boundary condition" (possibly an array index overflow), a different vulnerability than CVE-2006-3434, CVE-2006-3650, and CVE-2006-3868.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 6.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
1 source links · newest first
- Find potential exploit conditions in Microsoft Office documentsHelp Net Security
OfficeCat is a command line utility developed by the Sourcefire VRT that can be used to process Microsoft Office Documents to determine the presence of potential exploit conditions in the file. Officecat is available for Windows and Linux. Vulnerabilities checked by OfficeCat: CVE-2006-0001 CVE-2006-1301 CVE-2006-1306 CVE-2006-1308 CVE-2006-1540 CVE-2006-2492 CVE-2006-3014 CVE-2006-3086 CVE-2006-3431 CVE-2006-3432 CVE-2006-3493 CVE-2006-3590 CVE-2006-3656 CVE-2006-3864 CVE-2006-3865 CVE-2006-3875 CVE-2006-3876 CVE-2006-3877 CVE-2006-4534 CVE-2006-4694 CVE-2006-4700 CVE-2006-4701 CVE-2006-5994 CVE-2006-5995 CVE-2006-6456 CVE-2006-6561 CVE-2007-0027 CVE-2007-0030 CVE-2007-0031 CVE-2007-0515 CVE-2007-0671 CVE-2007-1203 CVE-2007-1214 … More →
newswww.helpnetsecurity.comNov 2, 2009, 3:02 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2009-2528CVSS 9.3 · Critical
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Off…
- CVE-2009-2503CVSS 9.3 · Critical
GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Projec…
- CVE-2006-3877CVSS 9.3 · Critical
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute a…
- CVE-2008-1089CVSS 9.3 · Critical
Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file contai…
- CVE-2020-0760CVSS 8.8 · High
A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE…
- CVE-2009-3126CVSS 9.3 · Critical
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 200…