CVE-2013-3158
published 2013-09-11CVE-2013-3158: Microsoft Excel 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office…
PriorityP350critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
18.78%
97.0th percentile
Microsoft Excel 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | excel | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5cj3-4rxh-xm4j: Microsoft Excel 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted
ghsa_unreviewed·2022-05-14
CVE-2013-3158 [HIGH] CWE-119 GHSA-5cj3-4rxh-xm4j: Microsoft Excel 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted
Microsoft Excel 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
Red Hat
xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
vendor_redhat·2016-03-24·CVSS 4.3
CVE-2016-3158 [MEDIUM] xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
Statement: This issue does not affect the Xen hypervisor packages as shipped with Red Hat Enterprise Linux 5.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
No detection rules found.
No public exploits indexed.
http://www.us-cert.gov/ncas/alerts/TA13-253Ahttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-073https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18984http://www.us-cert.gov/ncas/alerts/TA13-253Ahttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-073https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18984
2013-09-11
Published