CVE-2013-0086

Description

Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive information via a crafted OneNote file, aka Buffer Size Validation Vulnerability.

Risk Information

Base Score
5.5
MODERATE
Vector
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
34.206

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Microsoft OneNote 2010 (KB2760600) 32-Bit EditionWindows
Security Update for Microsoft OneNote 2010 (KB2760600) 64-Bit EditionWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-13322Security Update for Microsoft OneNote 2010 (KB2760600) 32-Bit Edition
PATCH-13323Security Update for Microsoft OneNote 2010 (KB2760600) 64-Bit Edition

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234