CVE Database
/

CVE-2011-0092

Back to search

CVE-2011-0092

Published: Feb 10, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

The LZW stream decompression functionality in ORMELEMS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 allows remote attackers to execute arbitrary code via a Visio file with a malformed VisioDocument stream that triggers an exception handler that accesses an object that has not been fully initialized, which triggers memory corruption, aka "Visio Object Memory Corruption Vulnerability."

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2011-0321
vdb-entry
x_refsource_VUPEN
MS11-008
vendor-advisory
x_refsource_MS
46137
vdb-entry
x_refsource_BID
1025043
vdb-entry
x_refsource_SECTRACK
70828
vdb-entry
x_refsource_OSVDB
43254
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:12403
vdb-entry
signature
x_refsource_OVAL

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now