CVE ALERT DETAIL : CVE-2008-0119


PRIMARYSOURCE

Source : cve
Description : Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka "Publisher Object Handler Validation Vulnerability."
INFORMATION
Name : CVE-2008-0119
First Publication : 2008-05-13
Last Modification : 2008-05-22
Severity : High
SCORING CVSS v2
Cvss Base Score : 9.3
Cvss Impact Score : 10
Cvss Expoit Score : 8.6
Attack Range : Network
Attack Complexity : Medium
Authentification : None Required

Calculate full CVSS 2.0 Vectors scores

OVALID

oval:org.mitre.oval:def:5303, Publisher Object Handler Validation Vulnerability

oval:org.mitre.oval:def:427, Microsoft Publisher 2000 is installed
oval:org.mitre.oval:def:734, Microsoft Publisher 2002 is installed
oval:org.mitre.oval:def:239, Microsoft Publisher 2003 is installed
oval:org.mitre.oval:def:2127, Microsoft Publisher 2007 is installed

CPE COMMON PLATEFORM ENUMERATION

Application : cpe:/a:microsoft:publisher:2000
Application : cpe:/a:microsoft:publisher:2002
Application : cpe:/a:microsoft:publisher:2003
Application : cpe:/a:microsoft:publisher:2007



ADVERTISING


INTERNAL SOURCES (Detail)

CVSS
Name Severity Base Score Impact Score Exploit Score Attack Range Attack Complexity Auth
MS08-027 High (High) N/A N/A N/A Not Defined Not Defined Not Defined
 
MS08-012 High (High) N/A N/A N/A Not Defined Not Defined Not Defined
MS07-037 High (High) N/A N/A N/A Not Defined Not Defined Not Defined

IS IMPACTED


Software : Office 2000 SP3 (Microsoft)
Software : Office 2003 SP2 (Microsoft)
Software : Office 2003 SP3 (Microsoft)
Software : Office 2007 (Microsoft)
Software : Office 2007_sp1 (Microsoft)
Software : Office XP SP3 (Microsoft)

SECONDARY(S) SOURCE(S)