Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-1754

Опубликовано: 10 июл. 2007
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical pointers to NULL, aka the "Publisher Invalid Memory Reference Vulnerability".

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:microsoft:publisher:2007:*:*:*:*:*:*:*

EPSS

Процентиль: 98%
0.62213
Средний

9.3 Critical

CVSS2

Дефекты

CWE-399

Связанные уязвимости

github
почти 4 года назад

PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical pointers to NULL, aka the "Publisher Invalid Memory Reference Vulnerability".

EPSS

Процентиль: 98%
0.62213
Средний

9.3 Critical

CVSS2

Дефекты

CWE-399