CVE-2006-1301

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
13/07/2006
Last modified:
03/04/2025

Description

Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:excel:2000:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2000:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2000:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2000:sr1:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2002:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2002:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2002:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2003:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2004:*:mac_os_x:*:*:*:*:*
cpe:2.3:a:microsoft:excel:x:*:mac_os_x:*:*:*:*:*
cpe:2.3:a:microsoft:excel_viewer:2003:*:*:*:*:*:*:*