Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted TIFF image file, aka "GDI+ TIFF Buffer Overflow Vulnerability."
Project Subscriptions
| Vendors | Products |
|---|---|
|
Microsoft
Subscribe
|
.net Framework
Subscribe
Excel Viewer
Subscribe
Expression Web
Subscribe
Forefront Client Security
Subscribe
Internet Explorer
Subscribe
Office
Subscribe
Office Compatibility Pack
Subscribe
Office Excel Viewer
Subscribe
Office Groove
Subscribe
Office Powerpoint Viewer
Subscribe
Office Word Viewer
Subscribe
Platform Sdk
Subscribe
Project
Subscribe
Report Viewer
Subscribe
Sql Server
Subscribe
Sql Server Reporting Services
Subscribe
Visio
Subscribe
Visual Foxpro
Subscribe
Visual Studio
Subscribe
Visual Studio .net
Subscribe
Windows 2000
Subscribe
Windows 2003 Server
Subscribe
Windows Server 2008
Subscribe
Windows Vista
Subscribe
Windows Xp
Subscribe
Word Viewer
Subscribe
Works
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 21 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-120 | |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2024-10-21T16:34:33.080Z
Reserved: 2009-07-17T00:00:00
Link: CVE-2009-2502
Updated: 2024-08-07T05:52:14.805Z
Status : Deferred
Published: 2009-10-14T10:30:01.390
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-2502
No data.
OpenCVE Enrichment
No data.