Skip to main content

Vendor/product archive

microsoft / office_web_components CVEs

Beta · best-effort

13 CVEs tagged to microsoft / office_web_components5 Critical, 4 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2012-0158

Published Apr 10, 2012

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 G…

CVSS 8.8 · High
evidence mentions
132
Buzz score
72.5
KEV listed

CVE-2006-4695

Published Dec 31, 2006

Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via a crafted URL, aka "Of…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1338

Published Dec 18, 2002

The Load method in the Chart component of Office Web Components (OWC) 9 and 10 generates an exception when a specified file does not exist, which allows remote attackers to determ…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1339

Published Dec 18, 2002

The "XMLURL" property in the Spreadsheet component of Office Web Components (OWC) 10 follows redirections, which allows remote attackers to determine the existence of local files…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1340

Published Dec 18, 2002

The "ConnectionFile" property in the DataSourceControl component in Office Web Components (OWC) 10 allows remote attackers to determine the existence of local files by detecting a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0727

Published Sep 24, 2002

The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute a…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2002-0860

Published Sep 24, 2002

The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer v…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1