{"api_version":"1","generated_at":"2026-07-23T19:40:35+00:00","cve":"CVE-2002-0861","urls":{"html":"https://cve.report/CVE-2002-0861","api":"https://cve.report/api/cve/CVE-2002-0861.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0861","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0861"},"summary":{"title":"CVE-2002-0861","description":"Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the \"Allow paste operations via script\" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-09-24 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/4457","name":"http://www.securityfocus.com/bid/4457","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Office Web Components Clipboard Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-044","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-044","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS02-044 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/8779.php","name":"http://www.iss.net/security_center/static/8779.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"ISS X-Force Database: owc-spreadsheet-clipboard-access (8779): Microsoft OWC Spreadsheet component \"Paste\" and \"Copy\" method could allow unauthorized clipboard access through Internet Explorer","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=101829726516346&w=2","name":"http://marc.info/?l=bugtraq&m=101829726516346&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0861","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0861","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"861","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"office_web_components","cpe6":"2000","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"861","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"office_web_components","cpe6":"2002","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"861","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"project","cpe6":"2000","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"861","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"project","cpe6":"2002","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:03:48.970Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"owc-spreadsheet-clipboard-access(8779)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/8779.php"},{"name":"20020408 Controlling the clipboard with OWC in IE (GM#007-IE)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=101829726516346&w=2"},{"name":"4457","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4457"},{"name":"MS02-044","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-044"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-08-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the \"Allow paste operations via script\" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-12T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"owc-spreadsheet-clipboard-access(8779)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/8779.php"},{"name":"20020408 Controlling the clipboard with OWC in IE (GM#007-IE)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=101829726516346&w=2"},{"name":"4457","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4457"},{"name":"MS02-044","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-044"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0861","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the \"Allow paste operations via script\" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"owc-spreadsheet-clipboard-access(8779)","refsource":"XF","url":"http://www.iss.net/security_center/static/8779.php"},{"name":"20020408 Controlling the clipboard with OWC in IE (GM#007-IE)","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=101829726516346&w=2"},{"name":"4457","refsource":"BID","url":"http://www.securityfocus.com/bid/4457"},{"name":"MS02-044","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-044"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0861","datePublished":"2002-08-23T04:00:00.000Z","dateReserved":"2002-08-15T00:00:00.000Z","dateUpdated":"2024-08-08T03:03:48.970Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-09-24 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:office_web_components:2000:*:*:*:*:*:*:*","matchCriteriaId":"A431CA59-8BD3-48CB-82BC-8FDCFE7440FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:office_web_components:2002:*:*:*:*:*:*:*","matchCriteriaId":"316D6CD7-3B2B-499C-ADBE-088981DFD306"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:project:2000:*:*:*:*:*:*:*","matchCriteriaId":"3F09162C-01F0-4056-94D3-995713F92AE9"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:project:2002:*:*:*:*:*:*:*","matchCriteriaId":"2AE2D3E0-49E4-410E-B63A-753BDE8995BB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"861","Ordinal":"1","Title":"CVE-2002-0861","CVE":"CVE-2002-0861","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"861","Ordinal":"1","NoteData":"Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the \"Allow paste operations via script\" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object.","Type":"Description","Title":"CVE-2002-0861"},{"CveYear":"2002","CveId":"861","Ordinal":"2","NoteData":"2002-08-23","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"861","Ordinal":"3","NoteData":"2018-10-12","Type":"Other","Title":"Modified"}]}}}