Microsoft Visio vulnerabilities

54 known vulnerabilities affecting microsoft/visio.

Total CVEs
54
CISA KEV
2
actively exploited
Public exploits
8
Exploited in wild
1
Severity breakdown
CRITICAL32HIGH19MEDIUM3

Vulnerabilities

Page 3 of 3
CVE-2008-3015CRITICALCVSS 9.3v20022008-09-11
CVE-2008-3015 [CRITICAL] CWE-189 CVE-2008-3015: Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Mi Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remot
nvd
CVE-2008-3012CRITICALCVSS 9.3v20022008-09-11
CVE-2008-3012 [CRITICAL] CWE-119 CVE-2008-3012: gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 an gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 20
nvd
CVE-2008-1090CRITICALCVSS 9.3v2002v2003+3 more2008-04-08
CVE-2008-1090 [CRITICAL] CWE-399 CVE-2008-1090: Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows u Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a crafted .DXF file, aka "Visio Memory Validation Vulnerability."
nvd
CVE-2008-1089CRITICALCVSS 9.3v2002v2003+3 more2008-04-08
CVE-2008-1089 [CRITICAL] CWE-94 CVE-2008-1089: Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows u Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka "Visio Object Header Vulnerability."
nvd
CVE-2007-0934CRITICALCVSS 9.3v20022007-06-12
CVE-2007-0934 [CRITICAL] CVE-2007-0934: Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute a Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted version number that triggers memory corruption.
nvd
CVE-2007-0936CRITICALCVSS 9.3v20022007-06-12
CVE-2007-0936 [CRITICAL] CVE-2007-0936: Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted packed object that triggers memory corruption, aka "Visio Document Packaging Vulnerability."
nvd
CVE-2007-0671HIGHCVSS 8.8KEVv2002v20032007-02-03
CVE-2007-0671 [HIGH] CVE-2007-0671: Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Of Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
nvd
CVE-2006-5574CRITICALCVSS 9.3v20032006-12-31
CVE-2006-5574 [CRITICAL] CVE-2006-5574: Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and t Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and the Multilingual Interface for Office 2003, Project 2003, and Visio 2003 allows user-assisted remote attackers to execute arbitrary code via crafted text that is not properly parsed.
nvd
CVE-2006-3864CRITICALCVSS 9.3v20022006-10-10
CVE-2006-3864 [CRITICAL] CVE-2006-3864: Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoin Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file that triggers memory corruption, related to an "array boundary condition" (possibly an array index overflow)
nvd
CVE-2006-3877CRITICALCVSS 9.3v2002v20032006-10-10
CVE-2006-3877 [CRITICAL] CVE-2006-3877: Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2 Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
nvd
CVE-2005-2127HIGHCVSS 7.5PoCv2000v2002+1 more2005-08-19
CVE-2005-2127 [HIGH] CWE-119 CVE-2005-2127: Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (a Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.
nvd
CVE-2004-0848HIGHCVSS 7.5v20022005-02-08
CVE-2004-0848 [HIGH] CVE-2004-0848: Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.
nvd
CVE-2004-0200CRITICALCVSS 9.3PoCv2002v20032004-09-28
CVE-2004-0200 [CRITICAL] CVE-2004-0200: Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
nvd
CVE-2003-0347CRITICALCVSS 10.0PoCv20022003-10-20
CVE-2003-0347 [CRITICAL] CVE-2003-0347: Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.
nvd