Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2008-4837

Quick assessment

Affected
n/a n/a
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Word是微软Office套件中的文件处理工具。 Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, 和 2007 Gold和SP1; Word Viewer 2003 Gold 和 SP3; Office Compatibility Pack for Word, Excel, 和 PowerPoint 2007 File Formats Gold 和 SP1; 和 Microsoft Works 8 版本中存在栈缓冲区溢出漏洞,这允许远程攻击者通过一个

AI Predicted 9.3 Difficulty: Trivial EPSS 37.42% · P98
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2008-4837

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Stack-based buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; and Microsoft Works 8 allow remote attackers to execute arbitrary code via a crafted Word document that contains a malformed table property, which triggers memory corruption, aka "Word Memory Corruption Vulnerability."
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Microsoft Word畸形对象解析多个缓冲区溢出和内存破坏漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Word是微软Office套件中的文件处理工具。 Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, 和 2007 Gold和SP1; Word Viewer 2003 Gold 和 SP3; Office Compatibility Pack for Word, Excel, 和 PowerPoint 2007 File Formats Gold 和 SP1; 和 Microsoft Works 8 版本中存在栈缓冲区溢出漏洞,这允许远程攻击者通过一个
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2008-4837

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-4837

登录查看更多情报信息。

Vendor Advisories for CVE-2008-4837 (7)

Same Patch Batch · n/a · 2008-12-10 · 41 CVEs total

CVE-2008-5419 EMC ControlCenter SAN Manager SST_CTGTRANS远程栈溢出漏洞
CVE-2008-4264 Microsoft Excel畸形公式解析远程代码执行漏洞
CVE-2008-4265 Microsoft Excel畸形对象解析远程代码执行漏洞
CVE-2008-4266 Microsoft Excel数组内存破坏漏洞
CVE-2008-4268 Microsoft Windows保存搜索文件处理内存破坏漏洞
CVE-2008-4269 Microsoft Windows search-ms协议解析远程代码执行漏洞
CVE-2008-4841 Microsoft写字板文件转换器远程代码执行漏洞
CVE-2008-5416 Microsoft SQL Server sp_replwritetovarbin远程堆溢出漏洞
CVE-2008-5417 HP DECnet-Plus OpenVMS 'OSIT$NAMES'权限许可和访问控制漏洞
CVE-2008-5418 PUNBB PunPortal login.php目录遍历漏洞
CVE-2008-4261 Microsoft IE HTML渲染内存破坏漏洞
CVE-2008-5420 EMC ControlCenter SAN Manager SST_SENDFILE远程文件检索漏洞
CVE-2008-4311 D-Bus 规则绕过安全限制漏洞
CVE-2008-5304 TWiki URLPARAM变量跨站脚本漏洞
CVE-2008-5305 TWiki SEARCH变量SHELL命令注入漏洞
CVE-2008-5410 Sun Solaris OpenSSL 'PKCS#11' Engine 远程拒绝服务漏洞
CVE-2008-5411 IBM WebSphere应用程序服务器网络敏感信息泄露漏洞
CVE-2008-5412 IBM WebSphere Windows上的JSPs未明漏洞
CVE-2008-5413 IBM WebSphere PerfServlet信息泄露漏洞
CVE-2008-5414 IBM WebSphere Feature Pack未明漏洞

Showing top 20 of 41 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2008-4837

No comments yet


Leave a comment