VYPR
Unrated severityNVD Advisory· Published Oct 10, 2006· Updated Apr 23, 2026

CVE-2006-3650

CVE-2006-3650

Description

Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac do not properly parse the length of a chart record, which allows remote user-assisted attackers to execute arbitrary code via a Word document with an embedded malformed chart record that triggers an overwrite of pointer values with values from the document, a different vulnerability than CVE-2006-3434, CVE-2006-3864, and CVE-2006-3868.

Affected products

16
  • Microsoft/Office16 versions
    cpe:2.3:a:microsoft:office:2000:*:*:*:*:*:*:*+ 15 more
    • cpe:2.3:a:microsoft:office:2000:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:2000:*:*:ja:*:*:*:*
    • cpe:2.3:a:microsoft:office:2000:*:*:ko:*:*:*:*
    • cpe:2.3:a:microsoft:office:2000:sp1:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:2000:sp2:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:2000:*:*:zh:*:*:*:*
    • cpe:2.3:a:microsoft:office:2001:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:2001:*:*:*:*:mac_os:*:*
    • cpe:2.3:a:microsoft:office:2001:sr1:*:*:*:mac_os:*:*
    • cpe:2.3:a:microsoft:office:2003:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:2003:sp1:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:2003:sp2:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:2004:*:*:*:*:mac_os:*:*
    • cpe:2.3:a:microsoft:office:v.x:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

11

News mentions

0

No linked articles in our index yet.