Skip to main content

CVE detail

CVE-2010-3333

Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka "RTF Stack Buffer Overflow Vulnerability."

CVSS 7.8 · HighBuzz score 71.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 71.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
28 evidence mentions in the snapshot
Diversity score
16.0
6 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
28 source links · newest first
  • SentinelOne security researchers have analyzed the operations of a Chinese cyberespionage group that has been actively targeting education, government, and telecommunication organizations in Australia and Southeast Asia since at least 2013.

    newswww.securityweek.comJun 10, 2022, 11:37 AM
  • Researchers spotted a previously undocumented Chinese-speaking APT, tracked as Aoqin Dragon, targeting entities in Southeast Asia and Australia. SentinelOne documented a series of attacks aimed at government, education, and telecom entities in Southeast Asia and Australia carried out by a previously undocumented Chinese-speaking APT tracked as Aoqin Dragon. The APT primary focus on cyberespionage against targets […]

    newssecurityaffairs.comJun 9, 2022, 2:52 PM
  • The evolutions of APT28 attacksSecurity Affairs

    Analyzing how tactics, techniques and procedures of the Russia-linked APT28 cyberespionage group evolve over the time. APT28 is a well known Russian cyber espionage group attributed, with a medium level of confidence, to Russian military intelligence agency GRU (by CrowdStrike). It is also known as Sofacy Group (by Kaspersky) or STRONTIUM (by Microsoft) and it’s used to target Aereospace, Defence, Governmente Agencies, International […]

    newssecurityaffairs.comDec 5, 2019, 6:41 AM
  • Adobe’s Flash Player might be the most targeted product when criminal exploit kits are involved, but Microsoft products such as Office, Windows and Internet Explorer take center stage when Russian advanced persistent threat (APT) groups are involved.

    newswww.securityweek.comAug 5, 2016, 2:10 PM
  • Be the first to receive the latest news, cyber threat intelligence and research from Unit 42. Subscribe Now. Unit 42 is currently researching an attack campaign that targets government and military personnel of India. This attack appears to overlap with the Operation Transparent Tribe and Operation C-Major campaigns that targeted Indian embassies in Saudi Arabia

    vendorunit42.paloaltonetworks.comMar 25, 2016, 8:00 AM
  • On December 24, 2015, Unit 42 identified a targeted attack, delivered via email, on a high profile Indian diplomat, an Ambassador to Afghanistan. The body and content of the email suggest that it was crafted and spoofed to look like it was sent by the current Defence Minister of India, Mr. Manohar Parrikar, commending the

    vendorunit42.paloaltonetworks.comFeb 29, 2016, 3:00 PM
  • Executive Summary Over the past seven months, Unit 42 has been investigating a series of attacks we attribute to a group we have code named “Scarlet Mimic.” The attacks began over four years ago and their targeting pattern suggests that this adversary’s primary mission is to gather information about minority rights activists. We do not

    vendorunit42.paloaltonetworks.comJan 24, 2016, 3:00 PM
  • A three-year-old cyber operation is using a mix of social engineering, Microsoft Windows vulnerabilities and basic stenography to target government, military and industry officials in Taiwan and the Philippines, according to Trend Micro.

    newswww.securityweek.comMay 14, 2015, 6:07 PM
  • Sometimes “Patch Tuesday” comes and goes with little excitement or fanfare; yesterday was not one of those days. In just one day, Oracle released patches for 154 new vulnerabilities, Adobe issued updates for Flash and ColdFusion, and Microsoft released 24 patches of their own. On top of the sheer volume of patches, we learned that

    vendorunit42.paloaltonetworks.comOct 15, 2014, 4:45 PM
  • It was 2010 when the Stuxnet malware first appeared in the public consciousness. Though the years have passed however, there is no shortage of machines still vulnerable to attacks on one of the vulnerabilities the malware exploited as it trotted across the globe.

    newswww.securityweek.comAug 18, 2014, 11:28 PM
  • Zero-day vulnerabilities garner well-deserved attention, but often it is older vulnerabilities that are at the center of targeted attacks.

    newswww.securityweek.comMay 20, 2014, 7:22 PM
  • Researchers at Symantec say a sophisticated backdoor Trojan known as Egobot is targeting confidential information from South Korean companies as well as corporation doing business with South Korea.

    newswww.securityweek.comOct 15, 2013, 7:32 PM
  • An Advanced Persistent Threat (APT) called NetTraveler has been spotted making mischief again, but it appears to have learned a few new tricks since it was last spotted in June. The malware is now attacking a known Java vulnerability, CVE-2013-2465, and added water holing to its propagation strategy, according to new research from Kaspersky Lab. […]

    newswww.csoonline.comSep 4, 2013, 3:00 PM
  • The Malware Archives: MS Office FilesMalwarebytes Labs

    Recently, I posted a blog about analyzing PDF files. In that post, we covered some basics of the PDF format and…

    newswww.malwarebytes.comAug 18, 2013, 5:00 PM
  • Kaspersky Lab experts published a new research report about NetTraveler, which is a family of malicious programs used by APT actors to successfully compromise more than 350 high-profile victims in 40 countries. The NetTraveler group has infected victims across multiple establishments in both the public and private sector including government institutions, embassies, the oil and gas industry, research centers, military contractors and activists. According to Kaspersky Lab’s report, this threat actor has been active since … More →

    newswww.helpnetsecurity.comJun 5, 2013, 6:11 AM
  • WASHINGTON, DC – Kaspersky Lab researchers have uncovered yet another cyber-espionage campaign targeting unnamed “high profile” businesses and government agencies around the world, and are laying the blame at the door of a Chinese-based hacking crew.

    newswww.securityweek.comJun 4, 2013, 6:55 PM
  • A cyber-espionage campaign discovered by Kaspersky Lab has hit more than 350 businesses and government agencies throughout the world. According to Kaspersky Lab, the main tool used in the attacks is known as ‘NetTraveler,’ named after an internal string present in early versions of the malware. The group behind the attack is believed to have been active as early as 2004 – though the highest volume of activity occurred during the past three years.

    newswww.securityweek.comJun 4, 2013, 4:12 PM
  • An ongoing cyberespionage campaign compromised over 350 high-profile victims from more than 40 countries over the past eight years, including political activists, research centers, governmental institutions, embassies, military contractors and private companies from various industries. Researchers from antivirus vendor Kaspersky Lab named the campaign NetTraveler, after a string found in the main data stealing malware […]

    newswww.csoonline.comJun 4, 2013, 3:00 PM
  • The recently discovered cyber espionage campaign “Red October” has shocked world wide security community, the principal questions raised are: Who is behind the attacks? How is possible that for so long time the campaign went undetected? Which is the role of AV company in these operations? To try to understand who is behind the attacks […]

    newssecurityaffairs.comJan 17, 2013, 8:15 AM
  • On Monday, Kaspersky Lab uncovered details of a complex cyber espionage campaign dubbed ‘Operation Red October’ that has been targeting specific groups throughout the world for over five years.

    newswww.securityweek.comJan 15, 2013, 8:54 AM
  • Last October Kaspersky Lab’s Global Research & Analysis Team started a new investigation after several attacks hit computer networks of various international diplomatic service agencies. The attacks appeared very suspect, a new large scale cyber-espionage operation has been discovered, the operation is dubbed «Red October», a name inspired by famous novel «The Hunt For The Red […]

    newssecurityaffairs.comJan 15, 2013, 7:52 AM
  • Cyber security researchers have turned up evidence of a sophisticated cyber-espionage campaign that has been targeting political and business groups throughout the world for more than five years.

    newswww.securityweek.comJan 14, 2013, 1:15 PM
  • Dalai Lama + Mac OS X = APT with Tibet malwareSecurity Affairs

    Another excellent discovery of the active experts of Kaspersky Labs that have identified a new variant of the malware used in Tibet against Uyghur hacktivists, a Turkic ethnic group living in Eastern and Central Asia. The instance of Tibet malware detected infects OS X machines and is spread following a consolidated schema for politically motivated […]

    newssecurityaffairs.comJun 30, 2012, 1:45 PM
  • Most Popular Exploit Documents Used in April 2012 Trend Micro researchers recently offered a peek into just how prevalent the use of certain document types is among attackers.

    newswww.securityweek.comMay 14, 2012, 4:58 PM
  • Booby-trapped RTF documents are one of the most common types of malicious Microsoft Office files that are used to infect computers with advanced persistent threats (APTs), according to security researchers from Trend Micro. “Taking data from exploit documents gathered last April, we can see that the most exploited MS Office software is MS Word,” said […]

    newswww.csoonline.comMay 10, 2012, 3:00 PM
  • It’s three months to go until the start of the London Olympics 2012, and sports fans are searching for and buying tickets to the various events online. Unfortunately, it’s inevitable that the interest surrounding such a huge global event will be misused by cyber criminals. Trend Micro researchers have recently spotted an email campaign that apparently warns users about Olympics-themed scams, and purportedly offers a list of bogus sites and organizations selling fake tickets: The … More →

    newswww.helpnetsecurity.comApr 24, 2012, 8:39 AM
  • Recently experts monitored several targeted attacks against Tibetan activist organizations including the International Campaign for Tibet and the Central Tibet Administration. Researchers suspect the involvement of China and on groups of hackers sponsored by the Beijing government. In multiple cases, we have seen how the Chinese government promotes and supports from the economic point of view […]

    newssecurityaffairs.comApr 2, 2012, 9:30 AM
  • Hackers are using a recent report about cyberthreats to Tibetan activists as a lure in a new attack against pro-Tibet organizations that distributes Windows and Mac malware, researchers from security vendor AlienVault said on Monday. On March 13, AlienVault published a report about email-based cyberattacks against Tibetan activist organizations including the Central Tibet Administration and […]

    newswww.csoonline.comMar 21, 2012, 3:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence