CVE-2011-0980
Summary
| CVE | CVE-2011-0980 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-02-10 19:00:00 UTC |
| Updated | 2018-10-12 21:59:00 UTC |
| Description | Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art objects, which allows remote attackers to execute arbitrary code via vectors related to a function pointer, aka "Excel Dangling Pointer Vulnerability." |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Excel | 2002 | sp3 | All | All |
| Application | Microsoft | Excel | 2003 | All | All | All |
| Application | Microsoft | Excel | 2003 | sp3 | All | All |
| Application | Microsoft | Excel | 2002 | sp3 | All | All |
| Application | Microsoft | Excel | 2003 | All | All | All |
| Application | Microsoft | Excel | 2003 | sp3 | All | All |
| Application | Microsoft | Office | 2004 | All | mac | All |
| Application | Microsoft | Office | 2008 | All | mac | All |
| Application | Microsoft | Office | 2004 | All | mac | All |
| Application | Microsoft | Office | 2008 | All | mac | All |
| Application | Microsoft | Open Xml File Format Converter | All | All | mac | All |
| Application | Microsoft | Open Xml File Format Converter | All | All | mac | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Office Excel Invalid Object Type Vulnerability - Secunia.com | SECUNIA | secunia.com | |
| Zero Day Initiative | MISC | zerodayinitiative.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| SecurityTracker: Microsoft Excel Multiple Bugs Let Remote Users Execute Arbitrary Code | SECTRACK | www.securitytracker.com | |
| Microsoft Security Bulletin MS11-021 - Important | Microsoft Docs | MS | docs.microsoft.com | |
| US-CERT Technical Cyber Security Alert TA11-102A -- Microsoft Updates for Multiple Vulnerabilities | CERT | www.us-cert.gov | US Government Resource |
| Microsoft Excel Multiple Vulnerabilities - Secunia.com | SECUNIA | secunia.com | |
| TippingPoint | DVLabs | ZDI Public Disclosure: Microsoft | MISC | dvlabs.tippingpoint.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.