Microsoft / Office Web Components
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2012-1856 KEV | The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Offi… | HIGH | 8.8 | Aug 15, 2012 |
| CVE-2012-0158 KEV | The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2… | HIGH | 8.8 | Apr 10, 2012 |
| CVE-2009-2496 | Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003… | HIGH | 9.3 | Aug 12, 2009 |
| CVE-2009-1534 | Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk… | HIGH | 9.3 | Aug 12, 2009 |
| CVE-2009-0562 | The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 200… | HIGH | 9.3 | Aug 12, 2009 |
| CVE-2009-1136 | The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Compon… | HIGH | 9.3 | Jul 15, 2009 |
| CVE-2006-4695 | Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via a… | HIGH | 9.3 | Mar 11, 2008 |
| CVE-2002-0860 | The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through… | MEDIUM | 5.0 | Apr 2, 2003 |
| CVE-2002-0727 | The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote at… | HIGH | 7.5 | Apr 2, 2003 |
| CVE-2002-1340 | The "ConnectionFile" property in the DataSourceControl component in Office Web Components (OWC) 10 allows remote attackers to determine the existence of local… | MEDIUM | 5.0 | Dec 11, 2002 |
| CVE-2002-1339 | The "XMLURL" property in the Spreadsheet component of Office Web Components (OWC) 10 follows redirections, which allows remote attackers to determine the exist… | MEDIUM | 5.0 | Dec 11, 2002 |
| CVE-2002-1338 | The Load method in the Chart component of Office Web Components (OWC) 9 and 10 generates an exception when a specified file does not exist, which allows remote… | MEDIUM | 5.0 | Dec 11, 2002 |
| CVE-2002-0861 | Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled… | HIGH | 7.5 | Aug 23, 2002 |
Showing 1 to 13 of 13 CVEs