CVE-2010-3946
Microsoft Office - Remote Code Execution via PICT Image Converter Integer Overflow
Title source: llmDescription
Integer overflow in the PICT image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted PICT image in an Office document, aka "PICT Image Converter Integer Overflow Vulnerability."
References (4)
Core 4
Core References
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA10-348A.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1024887
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11967
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-105
Scores
EPSS
0.2160
EPSS Percentile
97.4%
Details
CWE
CWE-189
Status
published
Products (3)
microsoft/office
2003 sp3
microsoft/office
xp sp3
microsoft/office_converter_pack
Published
Dec 16, 2010
Tracked Since
Feb 18, 2026