CVE-2008-2244
published 2008-07-09CVE-2008-2244: Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July…
PriorityP272critical9.3CVSS 2.0
AVNACMAuNCCICAC
ITWVulnCheck KEV
Exploited in the wild
EPSS
32.14%
98.1th percentile
Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July 2008, and as demonstrated by attachement.doc.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office_word | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.3CRITICAL
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w7r7-qgmj-q7fh: Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a
ghsa_unreviewed·2022-05-01
CVE-2008-2244 [HIGH] GHSA-w7r7-qgmj-q7fh: Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a
Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July 2008, and as demonstrated by attachement.doc.
VulnCheck
Microsoft Office Word 2002 SP3 Malformed Data Remote Code Execution
vulncheck·2008·CVSS 9.3
CVE-2008-2244 [CRITICAL] Microsoft Office Word 2002 SP3 Malformed Data Remote Code Execution
Microsoft Office Word 2002 SP3 Malformed Data Remote Code Execution
Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July 2008, and as demonstrated by attachement.doc.
Affected: Microsoft Office
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.cve.org/CVERecord?id=CVE-2008-2244; https://cisa.gov/news-events/alerts/2015/04/29/top-30-targeted-high-risk-vulnerabilities; https://www.us-cert.gov/ncas/alerts/TA15-119A
Red Hat
avahi: assertion failure after receiving a packet with corrupted checksum
vendor_redhat·2010-06-23·CVSS 5.0
CVE-2010-2244 [MEDIUM] avahi: assertion failure after receiving a packet with corrupted checksum
avahi: assertion failure after receiving a packet with corrupted checksum
The AvahiDnsPacket function in avahi-core/socket.c in avahi-daemon in Avahi 0.6.16 and 0.6.25 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNS packet with an invalid checksum followed by a DNS packet with a valid checksum, a different vulnerability than CVE-2008-5081.
Package: avahi (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
Qualys
US-CERT: Top 30 Vulnerabilities | Qualys
blogs_qualys·2015-05-01·CVSS 2.6
[LOW] US-CERT: Top 30 Vulnerabilities | Qualys
On April 29, 2015 US-CERT published TA15-119A which describes the Top 30 vulnerabilities that critical infrastructure organizations should focus on because they are under attack all the time. The list contains Windows, Internet Explorer, Adobe Software from Reader, Flash to Cold Fusion, Java from Oracle and others and is quite similar to the more generic set of software packages published by the German BSI last December.
Here is a list of the vulnerabilities in the advisory. I have reordered and optimized where possible for efficient scanning with Qualys, for example listing the most recent patch first to take advantage of superseding patches:
- Windows: MS14-060 for CVE-2014-4114, Qualys ID: 90979
- Internet Explorer: MS14-021 for CVE-2014-1776, Qualys ID: 100191
- MS14-012 for CVE-201
Qualys
US-CERT: Top 30 Vulnerabilities | Qualys
blogs_qualys·2015-05-01·CVSS 2.6
[LOW] US-CERT: Top 30 Vulnerabilities | Qualys
On April 29, 2015 US-CERT published TA15-119A which describes the Top 30 vulnerabilities that critical infrastructure organizations should focus on because they are under attack all the time. The list contains Windows, Internet Explorer, Adobe Software from Reader, Flash to Cold Fusion, Java from Oracle and others and is quite similar to the more generic set of software packages published by the German BSI last December.
Here is a list of the vulnerabilities in the advisory. I have reordered and optimized where possible for efficient scanning with Qualys, for example listing the most recent patch first to take advantage of superseding patches:
Windows: MS14-060 for CVE-2014-4114, Qualys ID: 90979
MS14-012 for CVE-2014-0322
MS13-038 for CVE-2013-1347
MS13-008 for CVE-2012-4792
MS10-01
Bugzilla
CVE-2010-2244 avahi: assertion failure after receiving a packet with corrupted checksum
bugzilla·2010-06-23·CVSS 5.0
CVE-2010-2244 [MEDIUM] CVE-2010-2244 avahi: assertion failure after receiving a packet with corrupted checksum
CVE-2010-2244 avahi: assertion failure after receiving a packet with corrupted checksum
Ludwig Nussel reported:
[1] http://www.openwall.com/lists/oss-security/2010/06/23/4
a deficiency in the way avahi daemon processed packets with corrupted
checksum(s). A remote attacker on the same local are network (LAN)
could send a DNS packet with broken checksum, that would cause avahi-daemon
to exit unexpectedly due to a failed assertion check. Different vulnerability
than CVE-2008-5081.
Discussion:
Created attachment 426335
Proposed patch by Ludwig Nussel (from [1])
---
Created avahi tracking bugs for this issue
Affects: fedora-all [bug 607297]
---
This has been assigned CVE-2010-2244.
---
Lennart, have you had a chance to review the patch Ludwig provided to fix this yet?
---
This issu
http://blogs.technet.com/msrc/archive/2008/07/08/vulnerability-in-microsoft-word-could-allow-remote-code-execution.aspxhttp://isc.sans.org/diary.html?storyid=4696http://marc.info/?l=bugtraq&m=121915960406986&w=2http://secunia.com/advisories/30975http://www.microsoft.com/technet/security/advisory/953635.mspxhttp://www.securityfocus.com/bid/30124http://www.securitytracker.com/id?1020447http://www.us-cert.gov/cas/techalerts/TA08-225A.htmlhttp://www.vupen.com/english/advisories/2008/2028https://exchange.xforce.ibmcloud.com/vulnerabilities/43663https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5897http://blogs.technet.com/msrc/archive/2008/07/08/vulnerability-in-microsoft-word-could-allow-remote-code-execution.aspxhttp://isc.sans.org/diary.html?storyid=4696http://marc.info/?l=bugtraq&m=121915960406986&w=2http://secunia.com/advisories/30975http://www.microsoft.com/technet/security/advisory/953635.mspxhttp://www.securityfocus.com/bid/30124http://www.securitytracker.com/id?1020447http://www.us-cert.gov/cas/techalerts/TA08-225A.htmlhttp://www.vupen.com/english/advisories/2008/2028https://exchange.xforce.ibmcloud.com/vulnerabilities/43663https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5897
2008-07-09
Published
Exploited in the wild