CVE-2005-4131
Summary
| CVE | CVE-2005-4131 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-12-09 11:03:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involving an argument to the msvcrt.memmove function, aka "Brand new Microsoft Excel Vulnerability," as originally placed for sale on eBay as item number 7203336538. |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Excel | 2000 | All | All | All |
| Application | Microsoft | Excel | 2000 | sp2 | All | All |
| Application | Microsoft | Excel | 2000 | sp3 | All | All |
| Application | Microsoft | Excel | 2000 | sr1 | All | All |
| Application | Microsoft | Excel | 2002 | All | All | All |
| Application | Microsoft | Excel | 2002 | sp1 | All | All |
| Application | Microsoft | Excel | 2002 | sp2 | All | All |
| Application | Microsoft | Excel | 2002 | sp3 | All | All |
| Application | Microsoft | Excel | 2003 | All | All | All |
| Application | Microsoft | Excel | 2003 | sp1 | All | All |
| Application | Microsoft | Excel | 95 | All | All | All |
| Application | Microsoft | Excel | 97 | All | All | All |
| Application | Microsoft | Excel | 97 | sr1 | All | All |
| Application | Microsoft | Excel | 97 | sr2 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityReason | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www.osvdb.org/blog | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| eBay halts auction of Excel flaw | Tech News on ZDNet | af854a3a-2127-422b-91ae-364da2661108 | news.zdnet.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityReason | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Page not found | eWEEK | af854a3a-2127-422b-91ae-364da2661108 | www.eweek.com | |
| Microsoft Excel Malformed Range Memory Corruption Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| Zero-day Excel flaw for sale on eBay - Breaking - Technology - theage.com.au | af854a3a-2127-422b-91ae-364da2661108 | www.theage.com.au | |
| InformationWeek | Online Auctions, Security | Hacker Tries To Sell Excel Flaw On EBay | December 9, 2005 | af854a3a-2127-422b-91ae-364da2661108 | informationweek.com | |
| SecurityTracker.com Archives - Microsoft Excel Unspecified Stack Overflow May Let Remote Users Cause Arbitrary Code to Be Executed | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| cgi.ebay.com/ws/eBayISAPI.dll | af854a3a-2127-422b-91ae-364da2661108 | cgi.ebay.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| 1. Overview: | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| SecurityTracker.com Archives - Microsoft Office and Excel Buffer Overflows Let Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| eBay pulls vulnerability auction | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Microsoft Security Bulletin MS06-012 - Critical | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| news.com.com/2061-10789_3-5988086.html | af854a3a-2127-422b-91ae-364da2661108 | news.com.com | |
| Microsoft Office Multiple Code Execution Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| eBay pulls Excel vulnerability auction | The Register | af854a3a-2127-422b-91ae-364da2661108 | www.theregister.co.uk | |
| US-CERT Vulnerability Note VU#642428 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| US-CERT Technical Cyber Security Alert TA06-073A -- Microsoft Office and Excel Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Avaya Modular Messaging Windows Privilege Escalation Security Issues - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Daily Dose of Excel » Blog Archive » Excel Vulnerability For Sale | af854a3a-2127-422b-91ae-364da2661108 | www.dicks-blog.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Page not found | eWEEK | MITRE | www.eweek.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.