Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The XML parser in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013, and Office for Mac 2011, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory consumption and persistent application hang) via a crafted XML document containing a large number of nested entity references, as demonstrated by a crafted text/plain e-mail message to Outlook, a similar issue to CVE-2003-1564.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft Office XML解析器安全漏洞
Vulnerability Description
Microsoft Office是美国微软(Microsoft)公司开发的一款办公软件套件产品。常用组件有Word、Excel、Access、Powerpoint、FrontPage等。 Microsoft Office中的XML解析器存在安全漏洞,该漏洞源于程序没有正确检查递归。远程攻击者可借助特制的XML文档利用该漏洞造成拒绝服务(内存消耗和应用程序挂起)。以下版本受到影响:Microsoft Office 2007 SP3、2010 SP1和SP2、2013,Office for Mac 2011。
CVSS Information
N/A
Vulnerability Type
N/A