Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) selectors, related to a "memory handling error" that triggers memory corruption.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://www.securitytracker.com/id?1020014 | vdb entry |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-026 | vendor advisory |
http://www.vupen.com/english/advisories/2008/1504/references | vdb entry vendor advisory |
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=700 | third party advisory |
http://marc.info/?l=bugtraq&m=121129490723574&w=2 | vendor advisory |
http://secunia.com/advisories/30143 | third party advisory vendor advisory |
http://www.us-cert.gov/cas/techalerts/TA08-134A.html | third party advisory us government resource |
http://www.securityfocus.com/bid/29105 | patch vdb entry |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5012 | signature vdb entry |