Microsoft Visual Basic vulnerabilities
19 known vulnerabilities affecting microsoft/visual_basic.
Total CVEs
19
CISA KEV
2
actively exploited
Public exploits
8
Exploited in wild
3
Severity breakdown
CRITICAL10HIGH7MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2012-1856HIGHCVSS 8.8KEVv6.02012-08-15
CVE-2012-1856 [HIGH] CVE-2012-1856: The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Of
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integrat
nvd
CVE-2012-0158HIGHCVSS 8.8KEVPoCv6.02012-04-10
CVE-2012-0158 [HIGH] CWE-94 CVE-2012-0158: The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold
nvd
CVE-2008-4255CRITICALCVSS 9.3PoCv6.02008-12-10
CVE-2008-4255 [CRITICAL] CWE-119 CVE-2008-4255: Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animatio
Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute arbitrary code via an AVI file
nvd
CVE-2008-4253HIGHCVSS 8.5v6.02008-12-10
CVE-2008-4253 [HIGH] CWE-399 CVE-2008-4253: The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP
The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project 2003 SP3 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "
nvd
CVE-2008-4256HIGHCVSS 8.5v6.02008-12-10
CVE-2008-4256 [HIGH] CWE-399 CVE-2008-4256: The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1,
The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state,
nvd
CVE-2008-4254HIGHCVSS 8.5v6.02008-12-10
CVE-2008-4254 [HIGH] CWE-189 CVE-2008-4254: Multiple integer overflows in the Hierarchical FlexGrid ActiveX control (mshflxgd.ocx) in Microsoft
Multiple integer overflows in the Hierarchical FlexGrid ActiveX control (mshflxgd.ocx) in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allow remote attackers to execute arbitrary code via crafted (1) Rows and (2) Cols properties to the (a) ExpandAll and (b) CollapseAll methods, related to access of incorrectly initialized obje
nvd
CVE-2008-4252HIGHCVSS 8.5v6.02008-12-10
CVE-2008-4252 [HIGH] CWE-264 CVE-2008-4252: The DataGrid ActiveX control in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and
The DataGrid ActiveX control in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "DataGrid Control Memory Corruptio
nvd
CVE-2008-3704CRITICALCVSS 9.3ExploitedPoCv6.02008-08-18
CVE-2008-3704 [CRITICAL] CWE-119 CVE-2008-3704: Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, re
nvd
CVE-2007-0065CRITICALCVSS 10.0v6.02008-02-12
CVE-2007-0065 [CRITICAL] CWE-94 CVE-2007-0065: Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 200
Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request.
nvd
CVE-2008-0392CRITICALCVSS 9.3PoCv6.02008-01-23
CVE-2008-0392 [CRITICAL] CWE-119 CVE-2008-0392: Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted r
Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .dsr file with a long (1) ConnectionName or (2) CommandName line.
nvd
CVE-2007-4776CRITICALCVSS 9.3PoCv6.02007-09-10
CVE-2007-4776 [CRITICAL] CWE-119 CVE-2007-4776: Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted re
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a Visual Basic project (vbp) file containing a long Reference line, related to VBP_Open and OLE. NOTE: there are limited usage scenarios under which this would be a vulnerability.
nvd
CVE-2007-2224CRITICALCVSS 9.3v6.02007-08-14
CVE-2007-2224 [CRITICAL] CWE-119 CVE-2007-2224: Object linking and embedding (OLE) Automation, as used in Microsoft Windows 2000 SP4, XP SP2, Server
Object linking and embedding (OLE) Automation, as used in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Office 2004 for Mac, and Visual Basic 6.0 allows remote attackers to execute arbitrary code via the substringData method on a TextNode object, which causes an integer overflow that leads to a buffer overflow.
nvd
CVE-2007-2884CRITICALCVSS 9.3PoCv6.02007-05-30
CVE-2007-2884 [CRITICAL] CWE-20 CVE-2007-2884: Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attacke
Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption) or execute arbitrary code via a Visual Basic Project (vbp) file with a long (1) Description or (2) Company Name (VersionCompanyName) field.
nvd
CVE-2006-4732CRITICALCVSS 10.0v6.02006-09-13
CVE-2006-4732 [CRITICAL] CVE-2006-4732: Unspecified vulnerability in Microsoft Visual Basic (VB) 6 has an unknown impact ("overflow") via a
Unspecified vulnerability in Microsoft Visual Basic (VB) 6 has an unknown impact ("overflow") via a project that contains a certain Click event procedure, as demonstrated using the msgbox function and the VB.Label object.
nvd
CVE-2006-3649MEDIUMCVSS 5.1v6.2v6.3+1 more2006-08-09
CVE-2006-3649 [MEDIUM] CVE-2006-3649: Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Mic
Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via unspecified document properties that are not veri
nvd
CVE-2004-0200CRITICALCVSS 9.3PoCv2002v20032004-09-28
CVE-2004-0200 [CRITICAL] CVE-2004-0200: Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
nvd
CVE-2003-0347CRITICALCVSS 10.0PoCv5.0v6.2+1 more2003-10-20
CVE-2003-0347 [CRITICAL] CVE-2003-0347: Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA)
Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.
nvd
CVE-2001-0153HIGHCVSS 7.5v6.02001-05-03
CVE-2001-0153 [HIGH] CWE-119 CVE-2001-0153: Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition al
Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands.
nvd
CVE-1999-0384MEDIUMCVSS 4.6v5.01999-01-01
CVE-1999-0384 [MEDIUM] CVE-1999-0384: The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read
The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.
nvd