Vulnerability Details CVE-2004-0848
Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.275
EPSS Ranking 97.8%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2004-0848
-
cpe:2.3:a:microsoft:office:-
-
cpe:2.3:a:microsoft:office:16.0.14326.21330
-
cpe:2.3:a:microsoft:office:16.0.14326.21606
-
cpe:2.3:a:microsoft:office:16.0.14326.22331
-
cpe:2.3:a:microsoft:office:16.0.14326.22502
-
cpe:2.3:a:microsoft:office:16.0.14326.22618
-
cpe:2.3:a:microsoft:office:16.0.16026.20172
-
cpe:2.3:a:microsoft:office:16.0.16130.20156
-
cpe:2.3:a:microsoft:office:16.0.16827.20138
-
cpe:2.3:a:microsoft:office:16.0.18730.20000
-
cpe:2.3:a:microsoft:office:16.0.18827.20000
-
cpe:2.3:a:microsoft:office:16.0.19127.20000
-
cpe:2.3:a:microsoft:office:16.0.19220.20000
-
cpe:2.3:a:microsoft:office:16.0.19328.20000
-
cpe:2.3:a:microsoft:office:16.0.19426.20044
-
cpe:2.3:a:microsoft:office:16.0.19822.20000
-
cpe:2.3:a:microsoft:office:16.0.19822.20190
-
cpe:2.3:a:microsoft:office:2.70.23021003
-
cpe:2.3:a:microsoft:office:2000
-
cpe:2.3:a:microsoft:office:2001
-
cpe:2.3:a:microsoft:office:2002
-
cpe:2.3:a:microsoft:office:2003
-
cpe:2.3:a:microsoft:office:2004
-
cpe:2.3:a:microsoft:office:2007
-
cpe:2.3:a:microsoft:office:2008
-
cpe:2.3:a:microsoft:office:2010
-
cpe:2.3:a:microsoft:office:2011
-
cpe:2.3:a:microsoft:office:2013
-
cpe:2.3:a:microsoft:office:2013_rt
-
cpe:2.3:a:microsoft:office:2016
-
cpe:2.3:a:microsoft:office:2019
-
cpe:2.3:a:microsoft:office:2021
-
cpe:2.3:a:microsoft:office:2024
-
cpe:2.3:a:microsoft:office:3.0
-
cpe:2.3:a:microsoft:office:4.0
-
cpe:2.3:a:microsoft:office:4.3
-
cpe:2.3:a:microsoft:office:95
-
cpe:2.3:a:microsoft:office:97
-
cpe:2.3:a:microsoft:office:98
-
cpe:2.3:a:microsoft:office:xp
-
cpe:2.3:a:microsoft:powerpoint:2002
-
cpe:2.3:a:microsoft:project:2002
-
cpe:2.3:a:microsoft:visio:2002
-
cpe:2.3:a:microsoft:word:2002
-
cpe:2.3:a:microsoft:works:2002
-
cpe:2.3:a:microsoft:works:2003
-
cpe:2.3:a:microsoft:works:2004